Snort ids system visualization interface for alert analysis release_3x6ef3jqz5a35hzoompd25cfca

by Nadja Gavrilovic, Vladimir Ciric, Nikola Lozo

Published in Serbian Journal of Electrical Engineering by National Library of Serbia.

2022   Volume 19, p67-78

Abstract

Over the past decades, the rapid Internet development and the growth in the number of its users have raised various security issues. Therefore, it is of great importance to ensure the security of the network in order to enable the safe exchange of confidential data, as well as their integrity. One of the most important components of network attack detection is an Intrusion Detection System (IDS). Snort IDS is a widely used intrusion detection system, which logs alerts after detecting potentially dangerous network packets. A major challenge in network monitoring is the high volume of generated IDS alerts. A necessary step in successful network protection is the analysis of the great amount of logged alerts in search of deviations from normal traffic that may indicate an intrusion. The goal of this paper is to design and implement a visualization interface for IDS alert analysis, which graphically presents alerts generated by Snort IDS. Also, the proposed system classifies the alerts according to the most important attack parameters, and allows the users to understand evolving network situations and easily detect possible traffic irregularities. An environment in which the system has been tested in real-time is described, and the results of attack detection and classification are given. One of the detected attacks is analyzed in detail, as well as the method of its detection and its possible consequences.
In application/xml+jats format

Archived Files and Locations

application/pdf  759.6 kB
file_r22cvwlxqrhwfoaho4r4bl66ky
www.doiserbia.nb.rs (publisher)
web.archive.org (webarchive)
Read Archived PDF
Preserved and Accessible
Type  article-journal
Stage   published
Year   2022
Language   en ?
Journal Metadata
Open Access Publication
In DOAJ
In ISSN ROAD
Not in Keepers Registry
ISSN-L:  1451-4869
Work Entity
access all versions, variants, and formats of this works (eg, pre-prints)
Catalog Record
Revision: 814e5c53-1384-453e-906c-53e666e9b952
API URL: JSON