Ipsflow–uma proposta de sistema de prevençao de intrusao baseado no framework openflow
The ideal Intrusion Prevention System (IPS) is the one that detects malicious traffic across the network and blocks it at its source. Conventional IPSs do not meet these requirements satisfactorily, because when operating in active mode cannot have a wide coverage on the network and just block the passing traffic. And while catching mirrored traffic, it can only block it when working together with switches from the same solution or vendor. In this scenario, this paper presents IPSFlow, an IPS solution for selective and distributed capture with automated blocking of malicious traffic based on OpenFlow.