Chapter 13 - Describing Security Data Collection Flashcards

1
Q

Name 6 Monitoring Data Types

A
  1. Session Data
  2. Full Packet Capture
  3. Transaction Data
  4. Extracted Content
  5. Statistical Data
  6. Alert Data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Describe Session Data

A

Contains “5-tuple” for each session including timestamps and the amount of data transferred.
Example - NetFlow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Describe Full Packet Capture

A

A record containing all bits transferred on the wire.

Example - PCAP file / Wireshark

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Describe Transaction Data

A

The are usually produced by daemon or services and occur as a result of network sessions and system activities.
Example - HTTP or SMTP daemon logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Describe Extracted Content

A

Objects that are mined from network traffic.

Example - files downloaded from web site or email attachments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Describe Statistical Data

A

Takes other security monitoring data types and presents it at a higher level. Useful for forming baselines.
Example - Graph that shows web server connections per minute

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Describe Alert Data

A

Generally produced by IDS or IPS and triggered when traffic characteristics match a specific rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Define False Positive

A

When a security control acts when malicious activity did not take place

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Define False Negative

A

When a security control did not act when malicious activity did take place

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Define True Positive

A

When a security control acted when malicious activity did take place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define True Negative

A

When a security control did not act because there was no malicious activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly