Implementation of a Python-Based Network Intrusion Detection System for a University Computer Laboratory in Abuja

📖 ABSTRACT/OVERVIEW

University computer laboratories in Nigeria are increasingly targeted by network intrusions that compromise student data and institutional resources, yet many institutions in the FCT lack even basic intrusion detection infrastructure. This project implemented a Python-based network intrusion detection system (NIDS) for a university computer laboratory environment in Abuja, Federal Capital Territory. The system was built using Scapy for live packet capture and analysis on a dedicated monitoring machine connected to a managed switch's port mirror. Rule-based detection modules were developed to identify port scans, SYN flood attempts, ARP spoofing, and brute-force SSH login attempts. A SQLite database stored detected event logs, and a Flask web interface provided a real-time alert dashboard accessible to the laboratory administrator. The NIDS was evaluated using Metasploitable2 as an attack target and Kali Linux as the attack source in an isolated test environment. Detection accuracy for the four attack categories ranged from 87.3 percent for ARP spoofing to 96.7 percent for SYN flood detection. False positive rates were below 4 percent across all categories. Packet processing throughput reached 420 packets per second on a Core i5 monitoring machine before performance degradation was observed. The system generated email alerts within 12 seconds of threshold-crossing events. The study recommends implementing machine learning-based anomaly detection as a second detection layer to reduce false negatives for zero-day attack patterns in future iterations.

Keywords: intrusion detection system, network security, Python, university laboratory, Abuja

Need Complete Chapters of the Above Topic?

Get high-quality, Zero-AI research materials with current citations.

Request via WhatsApp 💬