OPTIMISING IPS RULES FOR EFFECTIVE DETECTION OF MULTI-VECTOR DDOS ATTACKS
Опубліковано 17.12.2024
Як цитувати
Завантаження
Авторське право (c) 2024 Vitaliy Tymoshchuk, Oleksandr Mykhailovskyi, Andrii Dolinskyi, Anastasiia Orlovska; Dmytro Tymoshchuk (Науковий керівник)

Ця робота ліцензується відповідно до Creative Commons Attribution-ShareAlike 4.0 International License.
Анотація
DDoS attacks have been and remain one of the biggest threats to information systems and networks. Multi-vector DDoS attacks, which combine several types of attacks simultaneously, are becoming increasingly common, making them difficult to neutralise. This article explores the use of optimised rules for a Snort-based intrusion detection and prevention system (IPS) in the pfSense environment. The methodology for developing and testing rules is presented, as well as experimental results that demonstrate an increase in detection efficiency and a decrease in false positives.
Посилання
- 1. What is a ddos attack? Ddos meaning, definition & types | fortinet. (n.d.). Fortinet. https://www.fortinet.com/resources/cyberglossary/ddos-attack
- 2. ТИМОЩУК, Д., & ЯЦКІВ, В. (2024). USING HYPERVISORS TO CREATE A CYBER POLYGON. MEASURING AND COMPUTING DEVICES IN TECHNOLOGICAL PROCESSES, (3), 52-56. https://doi.org/10.31891/2219-9365-2024-79-7
- 3. Тимощук, В., Долінський, А., & Тимощук, Д. (2024). ЗАСТОСУВАННЯ ГІПЕРВІЗОРІВ ПЕРШОГО ТИПУ ДЛЯ СТВОРЕННЯ ЗАХИЩЕНОЇ ІТ-ІНФРАСТРУКТУРИ. Матеріали конференцій МЦНД, (24.05. 2024; Запоріжжя, Україна), 145-146. https://doi.org/10.62731/mcnd-24.05.2024.001
- 4. Тимощук, В., & Тимощук, Д. (2022). Віртуалізація в центрах обробки даних-аспекти відмовостійкості. Матеріали Ⅹ науково-технічної конференції „Інформаційні моделі, системи та технології “Тернопільського національного технічного університету імені Івана Пулюя, 95-95.
- 5. PfSense documentation | pfsense documentation. (n.d.). Netgate Documentation | Netgate Documentation. https://docs.netgate.com/pfsense/en/latest/
- 6. Documents | Snort. Snort. (n.d.). https://www.snort.org/documents.
- 7. ParrotOS documentation | parrotos documentation. (n.d.). Parrot Security. https://parrotsec.org/docs/
- 8. Іваночко, Н., Тимощук, В., Букатка, С., & Тимощук, Д. (2023). РОЗРОБКА ТА ВПРОВАДЖЕННЯ ЗАХОДІВ ЗАХИСТУ ВІД UDP FLOOD АТАК НА DNS СЕРВЕР. Матеріали конференцій МНЛ, (3 листопада 2023 р., м. Вінниця), 177-178.
- 9. Демчук, В., Тимощук, В., & Тимощук, Д. (2023). ЗАСОБИ МІНІМІЗАЦІЇ ВПЛИВУ SYN FLOOD АТАК. Collection of scientific papers «SCIENTIA», (November 24, 2023; Kraków, Poland),
- 130-130.
- 10. Tymoshchuk, D., & Yatskiv, V. (2024). SLOWLORIS DDOS DETECTION AND PREVENTION IN REAL-TIME. Collection of scientific papers «ΛΌГOΣ», (August 16, 2024; Oxford, UK), 171-176. https://doi.org/10.36074/logos-16.08.2024.036
