2 - IDS Flashcards

1
Q

IDS

A

Intrusion Detection Systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define an intrusion

A

Set of actions aimed to compromise security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Activity is suspicious (IDS) if

A
  1. Matches a pattern for known malicious activity
  2. Differs significantly from previous patterns of use.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

IDS Components

A

Audit Data Preprocessor
Detection Engine (+Models)
Decision Engine (+Table)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

IDS Functions

A
  1. Monitor activity
  2. Audit Sys config
  3. Assess system integrity
  4. Recognise known attacks
  5. Indentify abnormal activity
  6. Manage audit trails
  7. Correct config errors
  8. Install/open traps to record info
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

IDS Types

A
  • Network (links/backbones)
  • Host (OS)
  • Distributed (group of remote sensor IDSes)
  • Gateway (deployed at gateway)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

IDS responses

A

Alarm
Cut user access
Reject traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

IDS Problems

A
  • Inaccuracy for exploit based signatures
  • Cannot recognise unknown intrusions
  • Cannot provide quality forensics info
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

IDS before or after firewall

A

Before can be very slow but after might be quicker.

Before might be required to protect firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly