Hide metadata

dc.date.accessioned2013-03-12T08:06:00Z
dc.date.available2013-03-12T08:06:00Z
dc.date.issued2011en_US
dc.date.submitted2011-06-26en_US
dc.identifier.citationRødfoss, Jonas Taftø. Comparison of open source network intrusion detection systems. Masteroppgave, University of Oslo, 2011en_US
dc.identifier.urihttp://hdl.handle.net/10852/8951
dc.description.abstractMany companies and organizations offer IT-services (news papers, social sites, web developers and etc.) to the public, and those services needs to be protected. The amount of computer threats are increasing drastically, and many attacks are directed to those services companies offer. Larger companies have the economy to buy expensive security tools to protect their services, while smaller companies may have the same economy. Open source is an interesting field for those who do not have the need or the economy to buy expensive security solutions. Intrusion detection system is a well known security tool, and it could either be bought as a payment solution, or be downloaded from the web as an open source solution. Snort, Bro and Suricata are three different open source network intrusion detection systems. By comparing installation, configuration, alarms and information one can find out which solution that fits your network best. The process of setting up the test environment, installation and configuration of Snort, Bro and Suricata, and installation of Metasploit have been a time consuming process. Snort, Bro and Suricata have been tested in a network, and against a Metasploit framework with known exploits. Running Snort, Bro and Suricata in a network, have shown huge differences regarding the number of alarms produced, and also differences in the logs produced. The results after running Metasploit showed some unexpected but clarifying results in the logs created. The whole process has been evaluated, and there has been given a summary of Snort, Bro and Suricata regarding installation, configuration and alarms.eng
dc.language.isoengen_US
dc.titleComparison of open source network intrusion detection systemsen_US
dc.typeMaster thesisen_US
dc.date.updated2012-02-29en_US
dc.creator.authorRødfoss, Jonas Taftøen_US
dc.subject.nsiVDP::420en_US
dc.identifier.bibliographiccitationinfo:ofi/fmt:kev:mtx:ctx&ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:dissertation&rft.au=Rødfoss, Jonas Taftø&rft.title=Comparison of open source network intrusion detection systems&rft.inst=University of Oslo&rft.date=2011&rft.degree=Masteroppgaveen_US
dc.identifier.urnURN:NBN:no-29859en_US
dc.type.documentMasteroppgaveen_US
dc.identifier.duo130715en_US
dc.contributor.supervisorHårek Haugeruden_US
dc.identifier.bibsys120427346en_US
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/8951/1/Rodfoss.pdf


Files in this item

Appears in the following Collection

Hide metadata