Σχεδιασμός και αξιολόγηση εικονικής αρχιτεκτονικής δικτύου για δοκιμές κυβερνοασφάλειας
Design and evaluation of a virtual network architecture for cybersecurity testing

View/ Open
Keywords
pfsense ; Firewall ; Virtual environment ; ITZ ; ITZ ; NAT ; Port scanning ; Botnet attacks ; DoS ; DDoSAbstract
This thesis presents the design, implementation, and evaluation of a secure network infrastructure using the pfSense firewall in a virtualized environment. The project focuses on creating a controlled setup that separates network zones into an Internal Trusted Zone (ITZ) and a Demilitarized Zone (DMZ), integrating web servers and a database server. An attacker machine is introduced to simulate real-world threats, such as port scanning and Distributed Denial of Service (DDoS) attacks. The firewall was configured with specific rules and Network Address Translation (NAT) policies to ensure controlled access between the zones and the external network. The experimental results, based on network traffic analysis and attack simulations, demonstrate the efficiency of pfSense in defending against unauthorized access, while also highlighting the impact of DoS and botnet attacks on resource consumption. The findings provide valuable insights into firewall-based security architectures and underline the importance of layered defenses for modern networks.


