International Science and Technology Journal

Home < Articles < Article Details

Detection and Prevention of DDOS and HTTP Flood Attacks Using Snort Intrusion Detection Techniques

الملخص
أصبح أمن الشبكات تحديًا بالغ الأهمية للمؤسسات الحديثة نظرًا لتزايد الهجمات الإلكترونية. وتعاني العديد من الشركات من نقص أنظمة الأمان الآلية الذكية القادرة على اكتشاف التهديدات والاستجابة لها في الوقت الفعلي. تقدم هذه الورقة تصميم وتنفيذ نظام حماية ذكي للشبكات يعتمد على Snort 3 كنظام لكشف الاختراقات، بالإضافة إلى آليات استجابة آلية باستخدام iptables يراقب النظام المقترح حركة مرور الشبكة، ويكشف الأنشطة الضارة مثل هجمات حجب الخدمة (DDoS) وهجمات HTTP، ويحظر تلقائيًا عنوان IP الخاص بالمهاجم لفترة زمنية محددة. استُخدمت بنية قائمة على Bridge في تنفيذ النظام على خادم Ubuntu لضمان أداء ممتاز واستهلاك منخفض للموارد. تُظهر النتائج التجريبية أن الحل المقترح يكشف الهجمات بفعالية، ويقلل زمن الاستجابة، ويعزز أمن الشبكة بشكل عام..................... الكلمات المفتاحية:...... أمن الشبكات، (Snort 3)، نظام كشف التسلل، الاستجابة الآلية، iptables
Abstract
Network security has become a critical challenge for modern organizations due to the increasing number of cyber-attacks. Many businesses suffer from a lack of intelligent automated security systems capable of detecting and responding to threats in real time. This paper presents the design and implementation of an intelligent network protection system based on Snort 3 as an intrusion detection system combined with automated response mechanisms using iptables. The suggested system keeps an eye on network traffic, identifies malicious activity like DoS and HTTP attacks, and automatically blocks the attacker's IP address for a certain amount of time. A bridge-based architecture was used in the system's implementation on Ubuntu Server to guarantee excellent performance and minimal resource usage. Experimental results show that the proposed solution effectively detects attacks, reduces response time, and enhances overall network security.............. Keywords: ...........Network Security, Snort 3, Intrusion Detection System, Automated Response, iptables.