Analysis and design of intrusion detection system implementation / Chia Fook Keong

Nowadays, firewall has been widely used to enforce network security policy in organizations. However, maintaining a good and up to date security policy is not an easy task. Furthermore, maintaining a firewall is even harder. A slip of mouse will let the hackers to drive through the firewall easily....

Full description

Bibliographic Details
Main Author: Chia, Fook Keong
Format: Thesis
Published: 2003
Subjects:
Online Access:http://studentsrepo.um.edu.my/10010/
http://studentsrepo.um.edu.my/10010/1/Chia_Fook_Keong.pdf
_version_ 1848774025100132352
author Chia, Fook Keong
author_facet Chia, Fook Keong
author_sort Chia, Fook Keong
building UM Research Repository
collection Online Access
description Nowadays, firewall has been widely used to enforce network security policy in organizations. However, maintaining a good and up to date security policy is not an easy task. Furthermore, maintaining a firewall is even harder. A slip of mouse will let the hackers to drive through the firewall easily. Sometime, a badly configured firewall will engender a false sense of security. This can be worse than no firewall at all. As such, Intrusion Detection System (IDS) has been introduced as a second line of defense to protect an organization. IDS can be either host-based, network based or integrated. The functions of IDS include continuous monitoring and analysis of users and system activities as well as auditing system configurations and vulnerabilities. This report studies the implementation issues of IDS. The IDS chosen was Snort, which is a free, open source, lightweight, multi-platform and customizable software. The Faculty of Computer Science and Information Technology (FCSIT), University of Malaya network has been chosen as the testing site, First, this study analyzes the environment and protocols run in the FCSIT network. The study finds that FCSIT network has multiple virtual local area networks (VLANs) and is running Hot-Standby Routing Protocol (HSRP) and Network Address Translation (NAT). Through the analysis, both HSRP and NAT affect the IDS implementation. Secondly, IDS is implemented in selected locations and the data gathered are analyzed. Network and system weaknesses discovered are rectified. The IDS is then fine tuned to reduce false alarm and improve detection performance. Through this, FCSIT network security is further enhanced.
first_indexed 2025-11-14T13:51:44Z
format Thesis
id um-10010
institution University Malaya
institution_category Local University
last_indexed 2025-11-14T13:51:44Z
publishDate 2003
recordtype eprints
repository_type Digital Repository
spelling um-100102021-07-08T05:37:03Z Analysis and design of intrusion detection system implementation / Chia Fook Keong Chia, Fook Keong QA75 Electronic computers. Computer science Nowadays, firewall has been widely used to enforce network security policy in organizations. However, maintaining a good and up to date security policy is not an easy task. Furthermore, maintaining a firewall is even harder. A slip of mouse will let the hackers to drive through the firewall easily. Sometime, a badly configured firewall will engender a false sense of security. This can be worse than no firewall at all. As such, Intrusion Detection System (IDS) has been introduced as a second line of defense to protect an organization. IDS can be either host-based, network based or integrated. The functions of IDS include continuous monitoring and analysis of users and system activities as well as auditing system configurations and vulnerabilities. This report studies the implementation issues of IDS. The IDS chosen was Snort, which is a free, open source, lightweight, multi-platform and customizable software. The Faculty of Computer Science and Information Technology (FCSIT), University of Malaya network has been chosen as the testing site, First, this study analyzes the environment and protocols run in the FCSIT network. The study finds that FCSIT network has multiple virtual local area networks (VLANs) and is running Hot-Standby Routing Protocol (HSRP) and Network Address Translation (NAT). Through the analysis, both HSRP and NAT affect the IDS implementation. Secondly, IDS is implemented in selected locations and the data gathered are analyzed. Network and system weaknesses discovered are rectified. The IDS is then fine tuned to reduce false alarm and improve detection performance. Through this, FCSIT network security is further enhanced. 2003 Thesis NonPeerReviewed application/pdf http://studentsrepo.um.edu.my/10010/1/Chia_Fook_Keong.pdf Chia, Fook Keong (2003) Analysis and design of intrusion detection system implementation / Chia Fook Keong. Undergraduates thesis, University of Malaya. http://studentsrepo.um.edu.my/10010/
spellingShingle QA75 Electronic computers. Computer science
Chia, Fook Keong
Analysis and design of intrusion detection system implementation / Chia Fook Keong
title Analysis and design of intrusion detection system implementation / Chia Fook Keong
title_full Analysis and design of intrusion detection system implementation / Chia Fook Keong
title_fullStr Analysis and design of intrusion detection system implementation / Chia Fook Keong
title_full_unstemmed Analysis and design of intrusion detection system implementation / Chia Fook Keong
title_short Analysis and design of intrusion detection system implementation / Chia Fook Keong
title_sort analysis and design of intrusion detection system implementation / chia fook keong
topic QA75 Electronic computers. Computer science
url http://studentsrepo.um.edu.my/10010/
http://studentsrepo.um.edu.my/10010/1/Chia_Fook_Keong.pdf