Proposed method demonstrates improved incident response in network security using zabbix and pfsense.
In the context of growing cyber threats, systems capable not only of detecting anomalies in the operation of network infrastructure but also of promptly responding to them without administrator intervention are becoming increasingly relevant. This paper proposes a method for automatic network reconfiguration based on the integration of the Zabbix monitoring system with the pfSense network gateway functionality. Such a system enables centralized control of the operating system status, resource usage, and network activity, while also allowing for automatic changes to host IP addresses, routing adaptation, and connection restrictions according to defined security policies. The aim of the study is to develop a method for automatic network monitoring and reconfiguration with dynamic IP address changes to improve the effectiveness of cyber threat mitigation. The object of the study is the processes of information security management in computer networks. The subject of the study includes methods of anomaly detection and automatic response through modification of network parameters using Zabbix and pfSense. In the context of automatic response to detected threats, the method of comprehensive monitoring of client host operating systems has been formalized, including subsequent analysis of logs, user actions, resource load, network port usage, and interaction with external services. A methodology for network reconfiguration after anomaly detection has been developed and implemented: in particular, changing the IP address while maintaining functionality in a minimal network access configuration and isolating the node using pfSense. Scripts for Windows client OS were employed, interacting with the Zabbix and pfSense APIs, thus ensuring dynamic and fully automated operation. Testing results of the proposed system in a simulated environment confirm its effectiveness. Compared to manual or partially automated solutions, incident response time was reduced, and the risk of attack propagation within the network was minimized.
No takes yet. Share an insight, caveat, or question.
Haidai et al. (2025) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: