Thesis Details

Potlačení DDoS útoků s využitím IDS/IPS

Bachelor's Thesis Student: Litwora Martin Academic Year: 2020/2021 Supervisor: Kučera Jan, Ing.
English title
Mitigation of DDoS Attacks Using IDS/IPS
Language
Czech
Abstract

This This bachelor's thesis focuses on the detection and mitigation of DDoS attacks (Distributed Denial of Service). The main goal is to analyze and practically verify the capabilities of various IDS/IPS, especially the open-source tool Suircata, to mitigate DDoS attacks. Three main DDoS attack groups are analyzed in this thesis. These groups are flood attacks, amplification attacks, and slow attacks. A set of rules has to be created for each attack type from these groups in order for Suricata to mitigate those DDoS attacks. This thesis also implements a set of tools and scripts to check the functionality and effectiveness of the created rules. These tools are used to generate selected DDoS attacks with different parameters. Testing took place in a virtual environment where special nodes had to be created which represent real subjects during a real DDoS attack. The set of tools and scripts was designed in a way that it can easily be used outside this virtual environment where it is possible to have larger network loads, various variants and combinations of systems, and more.

Keywords

IDS, IPS, Suricata, DDoS, DoS, Amplification attacks, Volumetric attacks, Slow attacks, DDoS mitigation

Department
Degree Programme
Information Technology
Files
Status
defended, grade C
Date
18 June 2021
Reviewer
Committee
Ryšavý Ondřej, doc. Ing., Ph.D. (DIFS FIT BUT), předseda
Hliněná Dana, doc. RNDr., Ph.D. (DMAT FEEC BUT), člen
Kořenek Jan, doc. Ing., Ph.D. (DCSY FIT BUT), člen
Křena Bohuslav, Ing., Ph.D. (DITS FIT BUT), člen
Szőke Igor, Ing., Ph.D. (DCGM FIT BUT), člen
Citation
LITWORA, Martin. Potlačení DDoS útoků s využitím IDS/IPS. Brno, 2021. Bachelor's Thesis. Brno University of Technology, Faculty of Information Technology. 2021-06-18. Supervised by Kučera Jan. Available from: https://www.fit.vut.cz/study/thesis/23121/
BibTeX
@bachelorsthesis{FITBT23121,
    author = "Martin Litwora",
    type = "Bachelor's thesis",
    title = "Potla\v{c}en\'{i} DDoS \'{u}tok\r{u} s vyu\v{z}it\'{i}m IDS/IPS",
    school = "Brno University of Technology, Faculty of Information Technology",
    year = 2021,
    location = "Brno, CZ",
    language = "czech",
    url = "https://www.fit.vut.cz/study/thesis/23121/"
}
Back to top