SUST Repository

EVALUATION PERFORMANCE OF SNORT NETWORK INTRUSION DETECTION SYSTEM

Show simple item record

dc.contributor.author Ibrahim, Eman Ahmed Alnour
dc.contributor.author Mohmed, Hadeel Siragaldeen Albdri
dc.contributor.author Abusham, Joudy Omer Abdallah
dc.contributor.author Ali, Marwa Ezuldeen Mohmed
dc.date.accessioned 2017-12-12T13:03:49Z
dc.date.available 2017-12-12T13:03:49Z
dc.date.issued 2017-10-01
dc.identifier.citation Ibrahim, Eman Ahmed Alnour.EVALUATION PERFORMANCE OF SNORT NETWORK INTRUSION DETECTION SYSTEM/Eman Ahmed Alnour Ibrahim...{etal};Ahmed Abdalla.-Khartoum : Sudan University of Science and Technology, College of Engineering,2017.-59p. :ill;28cm.- Bachelors search. en_US
dc.identifier.uri http://repository.sustech.edu/handle/123456789/19375
dc.description Bachelors search en_US
dc.description.abstract With the thriving technology and the great increase in the usage of computer networks, the risk of having these network to be under attacks have been increased. Number of techniques have been created and designed to help in detecting such attacks. One common technique is the use of Network Intrusion Detection System NIDS. Today, number of open sources and commercial Intrusion Detection Systems are available to match enterprises requirements but the performance of these Intrusion Detection Systems is still the main concern. In this research ,an open source snort was implemented on Linux platform used for testing, analyzing packets attacks in Defense advanced Research Project Agency 1999 and comparing the result of it with ground truth table to evaluate the accuracy and performance of snort according to different metrics (true positive ,false positive, false negative, true negative, speed of snort to capture packet and analyze).The precision of the snort became high because so many rules defined (true positive ) ,and still group of undefined rules false positive and false negative that effect the precision .The rustle of the obtained performance was medium ratio. Therefore , snort can deals better under that performance rate in offline traffic, if the rate becomes higher the performance will be reduced en_US
dc.description.sponsorship Sudan University of Science and Technology en_US
dc.language.iso en en_US
dc.publisher Sudan University of Science and Technology en_US
dc.subject SNORT NETWORK INTRUSION DETECTION SYSTEM en_US
dc.subject NETWORK INTRUSION en_US
dc.subject DETECTION SYSTEM en_US
dc.title EVALUATION PERFORMANCE OF SNORT NETWORK INTRUSION DETECTION SYSTEM en_US
dc.type Thesis en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Share

Search SUST


Browse

My Account