5-2 Flashcards
there are 6 basic approaches to IDS and IPS. some of these methods are implimented in various software packages and other are simply strategies that an organization can employ to decrease the likelihood of a ___________
successful intrusion
when ids was first developed _________ were generally used
hubs
with a hub a packet is sent from its _________________ via the IP address. when it arrives at its target network . then a mac address is used to find the target. be aware that all computers on this segment can see the packet, but since the mac address doesn’t match the other computers can ignore it.
source network to its destination network
sometimes called banishment vigilance, seeks to prevent intrusions before they occur. but can be complicated since it could block legitimate traffic
preemptive blocking
normally a software system will alert the administrator of suspicious. a human administrator will then decide whether or not to ______________. the preemptive looking technique should only be part of an overall intrusion detection strategy
block traffic
anomalies are detected in one of a few ways including
threshold monitoring
resource profiling
user/group work profiling
executable profiling
this technique involves actual software that works to detect intrusion attempts and notify the administrator
anomoly detection
this technique monitors preset acceptable behavior levels and observes whether these levels are exceeded
threshold monitoring
threshold provides a definition of __________ behavior
acceptable
indications of abnormal resource usage with resource profiling can be indicative of ____________
illicate activity
the enables the ids to id activity that might indicate an attack. once a potential danger is identified, the admin is contacted.
executalbe profiling
_______ is an element of data source that is of interest to the operator
activity
the ____________ is the person responsible for organizational security
administrator
the ids component that collects data and passes it to the analyzer for analysis
sensor
the component or process that analyzes the data collected by the sensor
analyzer