2 - IDS Flashcards
1
Q
IDS
A
Intrusion Detection Systems
2
Q
Define an intrusion
A
Set of actions aimed to compromise security
3
Q
Activity is suspicious (IDS) if
A
- Matches a pattern for known malicious activity
- Differs significantly from previous patterns of use.
4
Q
IDS Components
A
Audit Data Preprocessor
Detection Engine (+Models)
Decision Engine (+Table)
5
Q
IDS Functions
A
- Monitor activity
- Audit Sys config
- Assess system integrity
- Recognise known attacks
- Indentify abnormal activity
- Manage audit trails
- Correct config errors
- Install/open traps to record info
6
Q
IDS Types
A
- Network (links/backbones)
- Host (OS)
- Distributed (group of remote sensor IDSes)
- Gateway (deployed at gateway)
7
Q
IDS responses
A
Alarm
Cut user access
Reject traffic
…
8
Q
IDS Problems
A
- Inaccuracy for exploit based signatures
- Cannot recognise unknown intrusions
- Cannot provide quality forensics info
9
Q
IDS before or after firewall
A
Before can be very slow but after might be quicker.
Before might be required to protect firewall