Mestrado em Engenharia Inform´atica Disserta¸c~ao Relat´orioFinal Implementation of a distributed intrusion detection and reaction system Jo~aoPedro dos Santos Soares
[email protected] Orientador: Prof. Dr. Jorge Granjal Co-Orientador: Eng. Ricardo Ruivo Data: 1 de Setembro de 2016 1 Mestrado em Engenharia Inform´atica Disserta¸c~ao Relat´orioFinal Implementation of a distributed intrusion detection and reaction system Jo~aoPedro dos Santos Soares
[email protected] Orientador: Prof. Dr. Jorge Granjal Co-Orientador: Eng. Ricardo Ruivo J´uriArguente: Prof. Dr. M´arioRela J´uriVogal: Prof. Dr. Paulo Sim~oes Data: 1 de Setembro de 2016 3 Abstract Security was not always an important aspect in terms of networking and hosts. Nowa- days, it is absolutely mandatory. Security measures must make an effort to evolve at the same rate, or even at a higher rate, than threats, which is proving to be the most difficult of tasks. In this report we will detail the process of the implementation of a real distributed intrusion detection and reaction system, that will be responsible for securing a core set of networks already in production, comprising of thousands of servers, users and their respec- tive confidential information. Keywords: intrusion detection, intrusion prevention, host, network, security, threat, vul- nerability, hacking 5 Acknowledgments As we step into the most important project of my student life, there's a couple of people to whom I am extremely grateful, without them, this project and my life in general wouldn't be the same. I want to start by thanking my supervisor: Professor Jorge Granjal, who I quickly grew to admire for his dedication to this project.