Simulating model NIPDS for intrusion detection and prevention in telecommunication systems and networks
DOI:
https://doi.org/10.18372/2225-5036.20.6571Keywords:
protection of information, telecommunication systems and networks, system intrusion detection and prevention, imitating modelAbstract
The paper proposes a simulation model NIDPS (Network-based Intrusion Detection and Prevention System) for intrusion detection and prevention in telecommunication systems and networks. NIDPS package uses Wireshark to capture and implement procedures to filter traffic, the procedures of statistical data processing network traffic, testing hypotheses, processing the results and the decision of a malicious network activity that allows adaptively respond to the current situation, if necessary, to block suspicious traffic and send warning neighboring nodes in the network, the workstation network administrator logging server attacks, etc. The developed model can be interpreted as sensory and analytical part of the elementary network intrusion detection system based on statistical analysis.References
Карпук Н.М. Статистический анализ сетевого трафика. Электронная библиотека Белорусского государственного университета. — 2008. — С. 116-119.
NIST Special Publication 800-94. Guide to Intrusion Detection and Prevention Systems (IDPS). — Computer Security Division Information Technology Laboratory National Institute of Standards and Technology, Gaithersburg. — 127 p. (February 2007).
Brian Caswell, Jay Beale, Andrew Baker. Snort Intrusion Detection and Prevention Toolkit. — Syngress Media, U.S. 2006.
Ушаков Д.В. Развитие принципов функции-онирования систем обнаружения сетевых вторжений на основе модели защищенной распределенной системы: дис. канд. техн. наук: 05.13.19. — Москва, 2005. — 175 с.
Запечников С.В., Милославская Н.Г., Толстой А.И., Ушаков Д.В. Информационная безопасность открытых систем. Учебник для вузов. В 2-х томах. — М., 2008. — Т. ІІ: Средства защиты в сетях. — 558 с.
Олифер В.Г., Олифер Н.А. Компьютерные сети. Принципы, технологии, протоколы. — СПб.: Питер, 2010. — 944 с.
Downloads
Published
How to Cite
Issue
Section
License
The scientific journal "Ukrainian Scientific Journal of Information Security" adheres to the principles of open science and provides free, free and permanent access to all published materials. The goal of the policy is to increase the visibility, citation and impact of the results of scientific research in the field of information security. The journal works according to the principles of Open Access and does not charge a fee for access to published articles.
All articles are published in Open Access under the Creative Commons Attribution 4.0 International (CC BY 4.0) license.
Copyright
Authors who publish their works in the journal “Ukrainian Scientific Journal of Information Security”:
-
retain the copyright to their publications;
-
grant the journal the right of first publication of the article;
-
agree to the distribution of their materials under the CC BY 4.0 license;
-
have the right to reuse, archive, and distribute their works (including in institutional and subject repositories), provided that proper reference is made to the original publication in the journal.