Sistema de detección y prevención de intrusiones (IDPS) para mitigar vulnerabilidades en el acceso a la red de la Unidad Educativa “Pio Lopez”
Files
Date
2025-07
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
Technological advancement in educational institutions has generated growing concern about cybersecurity. Protection against cyberattacks is essential to ensure the confidentiality, integrity, and availability of information within the "Pío López" educational institution. In response to this need, an Intrusion Detection and Prevention System (IDPS) was developed to strengthen infrastructure security and mitigate threats in an academic environment. The methodology applied in this project is ISO/IEC 27001, which consisted of four phases. In the first phase, a risk analysis was performed using Nmap for port and system scanning, and OpenVAS for vulnerability detection, obtaining a detailed diagnosis of the infrastructure. Some vulnerabilities and default configurations of the technological equipment were recorded.
The second phase focused on the implementation of a centralized switch, an IDPS with Suricata, and integrating a visualization system with the ELK Stack. For the third phase, performance was evaluated through attack simulations, including Slowloris, DoS, and Man-in-the-Middle attacks, to verify the system's effectiveness, logging events, and proper operation. In the fourth phase, connection duration thresholds and data volumes were adjusted to improve the detection of slow attacks like Slowloris.
As a result, the developed system proved to be robust and scalable, with a low operating cost. It was able to detect suspicious behavior and mitigate attacks in real time, significantly improving the security of the institutional network.
The implemented IDPS provides a replicable model for other educational institutions, improving protection against cyberthreats.
Description
El avance tecnológico en instituciones educativas ha generado una creciente preocupación por la seguridad informática. La protección contra ataques cibernéticos es fundamental para garantizar la confidencialidad, integridad y disponibilidad de la información dentro de la institución educativa "Pío López". Ante esta necesidad, se desarrolló un Sistema de Detección y Prevención de Intrusiones (IDPS) con el propósito de fortalecer la seguridad de la infraestructura y mitigar amenazas en un entorno académico, la metodología aplicada dentro del presente proyecto es la ISO/IEC 27001 que consto con cuatro fases. En la primera etapa se realizó un análisis de riesgos empleando Nmap para el escaneo de puertos y sistemas, y OpenVAS para la detección de vulnerabilidades, obteniendo un diagnóstico detallado de la infraestructura. Se registraron algunas vulnerabilidades y configuraciones por defecto de los equipos tecnológicos.
La segunda fase se centró en la implementación de un switch centralizado, implementación de un IDPS con Suricata, integrando un sistema de visualización con ELK Stack. Para la tercera etapa se evaluó el funcionamiento a través de simulaciones de ataques, que incluyeron Slowloris, DoS, Man-in the-middle para verificar la efectividad del sistema, registrando los eventos y su correcto funcionamiento. En la cuarta fase se ajustaron umbrales de duración de conexiones y volúmenes de datos para mejorar la detección de ataques lentos como Slowloris.
Como resultado, el sistema desarrollado demostró ser robusto y escalable, con un bajo costo operativo. Logró detectar comportamientos sospechosos y mitigar ataques en tiempo real, mejorando significativamente la seguridad de la red institucional.
El IDPS implementado proporciona un modelo replicable para otras instituciones educativas, mejorando la protección contra ciberamenazas.
Keywords
ISO/IEC 27001, SEGURIDAD INFORMÁTICA EDUCATIVA, IDPS, VULNERABILIDADES, MITIGACIÓN, SURICATA