Back to Search Start Over

Snort ids system visualization interface for alert analysis

Authors :
Gavrilović Nađa
Ćirić Vladimir
Lozo Nikola
Source :
Serbian Journal of Electrical Engineering, Vol 19, Iss 1, Pp 67-78 (2022)
Publication Year :
2022
Publisher :
Faculty of Technical Sciences in Cacak, 2022.

Abstract

Over the past decades, the rapid Internet development and the growth in the number of its users have raised various security issues. Therefore, it is of great importance to ensure the security of the network in order to enable the safe exchange of confidential data, as well as their integrity. One of the most important components of network attack detection is an Intrusion Detection System (IDS). Snort IDS is a widely used intrusion detection system, which logs alerts after detecting potentially dangerous network packets. A major challenge in network monitoring is the high volume of generated IDS alerts. A necessary step in successful network protection is the analysis of the great amount of logged alerts in search of deviations from normal traffic that may indicate an intrusion. The goal of this paper is to design and implement a visualization interface for IDS alert analysis, which graphically presents alerts generated by Snort IDS. Also, the proposed system classifies the alerts according to the most important attack parameters, and allows the users to understand evolving network situations and easily detect possible traffic irregularities. An environment in which the system has been tested in real-time is described, and the results of attack detection and classification are given. One of the detected attacks is analyzed in detail, as well as the method of its detection and its possible consequences.

Details

Language :
English
ISSN :
14514869 and 22177183
Volume :
19
Issue :
1
Database :
Directory of Open Access Journals
Journal :
Serbian Journal of Electrical Engineering
Publication Type :
Academic Journal
Accession number :
edsdoj.43471b6d54c14caeaa97975c6393fa84
Document Type :
article
Full Text :
https://doi.org/10.2298/SJEE2201067G