Repository logo
Communities & Collections
All of DSpace
  • English
  • العربية
  • বাংলা
  • Català
  • Čeština
  • Deutsch
  • Ελληνικά
  • Español
  • Suomi
  • Français
  • Gàidhlig
  • हिंदी
  • Magyar
  • Italiano
  • Қазақ
  • Latviešu
  • Nederlands
  • Polski
  • Português
  • Português do Brasil
  • Srpski (lat)
  • Српски
  • Svenska
  • Türkçe
  • Yкраї́нська
  • Tiếng Việt
Log In
Have you forgotten your password?
  1. Home
  2. Browse by Author

Browsing by Author "Vaca Tonato, Kevin Jhonatan"

Filter results by typing the first few letters
Now showing 1 - 1 of 1
  • Results Per Page
  • Sort Options
  • No Thumbnail Available
    Item
    Sistema de detección de intrusos (IDS) en redes informáticas aplicando protocolos de ciberseguridad.
    (Universidad Técnica de Ambato. Facultad de Ingeniería en Sistemas Electrónica e Industrial. Carrera de Telecomunicaciones., 2026-07-09) Vaca Tonato, Kevin Jhonatan; Miniguano Miniguano, Livio Danilo; Universidad Técnica de Ambato. Facultad de Ingeniería en Sistemas Electrónica e Industrial. Carrera de Telecomunicaciones.
    This research focused on the design, implementation, and validation of a Host-based Intrusion Detection System (HIDS) using the open-source software Wazuh, aiming to strengthen cybersecurity on an application server running Moodle configured over Ubuntu. The methodology followed a quantitative and experimental approach within a controlled virtualized environment. To ensure system compatibility, a pre-operational version was installed, the ossec.conf file was modified, and system permissions were configured to guarantee full visibility over audit logs and kernel security modules, such as AppArmor. Attack simulations were executed from a Kali Linux virtual machine. In the first scenario, SSH authentication was evaluated using the Hydra tool; the system captured network packets in the auth.log file, demonstrating failed access attempts and displaying customized alerts on the main dashboard. In the second scenario, Denial of Service (DoS) attacks were conducted via TCP flooding. Tests showed that massive attacks disabled the host before it could report to the IDS. To mitigate this, a logical programming script was implemented to directly monitor the state of kernel sockets (netstat) and web server errors from an alternative virtual machine, successfully registering and detecting the DoS on time. Finally, an Active Response was executed, which isolated the attacking machine through a customized script responsible for shutting down the network interface, successfully mitigating the denial of service.

DSpace software copyright © 2002-2026 LYRASIS

  • Privacy policy
  • End User Agreement
  • Send Feedback
Repository logo COAR Notify