Thesis Details

Odvozování pravidel pro mitigaci DDoS

Master's Thesis Student: Hurta Marek Academic Year: 2016/2017 Supervisor: Žádník Martin, Ing., Ph.D.
English title
Deriving DDoS Mitigation Rules
Language
Czech
Abstract

This thesis is aimed at monitoring of computer networks using NetFlow data. It describes main aspects of detection network anomalies using IDS systems. Next part describes Nemea framework, which is used for creating modules. These modules are able to detect network incidents and attacks. Following chapters contain a brief overview of common network attacks with their specific remarks which can help in process of their detection. Based on this analysis, the concept of mitigation rules was created. These rules can be used for mitigation of DDoS attack. This method was tested on several data sets and it produced multiple mitigation rules. These rules were applied on data sets and they marked most of the suspicious flows.

Keywords

NetFlow, IDS systems, DDoS attack, Time machine system, Mitigation rules

Department
Degree Programme
Information Technology, Field of Study Information Technology Security
Files
Status
defended, grade A
Date
21 June 2017
Reviewer
Committee
Hanáček Petr, doc. Dr. Ing. (DITS FIT BUT), předseda
Bartík Vladimír, Ing., Ph.D. (DIFS FIT BUT), člen
Křivka Zbyněk, Ing., Ph.D. (DIFS FIT BUT), člen
Švéda Miroslav, prof. Ing., CSc. (DIFS FIT BUT), člen
Veselý Vladimír, Ing., Ph.D. (DIFS FIT BUT), člen
Zeman Václav, doc. Ing., Ph.D. (UTKO FEEC BUT), člen
Citation
HURTA, Marek. Odvozování pravidel pro mitigaci DDoS. Brno, 2017. Master's Thesis. Brno University of Technology, Faculty of Information Technology. 2017-06-21. Supervised by Žádník Martin. Available from: https://www.fit.vut.cz/study/thesis/19930/
BibTeX
@mastersthesis{FITMT19930,
    author = "Marek Hurta",
    type = "Master's thesis",
    title = "Odvozov\'{a}n\'{i} pravidel pro mitigaci DDoS",
    school = "Brno University of Technology, Faculty of Information Technology",
    year = 2017,
    location = "Brno, CZ",
    language = "czech",
    url = "https://www.fit.vut.cz/study/thesis/19930/"
}
Back to top