Intrusion Detection Systems Flashcards
A network faces three types of intruders: masquerade, misfeasor and clandestine. What do these terms mean?
Masquerade: outsider in general. An unauthorised user who penetrates a system to exploit another’s account
Misfeasor: insider in general. Legitimate user who misuses their privileges.
Clandestine: can be both. An individual who seizes supervisory control to evade auditing and access control.
What are some design goals of intrusion detection systems?
Detect a wide variety of intrusions, detect intrusions in real time, ensure accuracy.
Given the design goal “detect a wide variety of attacks”, how would this design goal be implemented?
Cover known and unknown attacks
Adapt to new attacks or changes in behaviour
Given the design goal “detect intrusions in real time”, how would this design goal be implemented?
Analyse user activities efficiently
Report suspicious cases in a timely way
Given the design goal “ensure accuracy”, how would this design goal be implemented?
Minimise false positives and false negatives
What are three types of IDS models?
Signature based, Anomaly based and Heuristic based
What is a signature based IDS?
A signature based IDS detects known attack signatures correspondingly. A signature in this context is a string or pattern that matches a known threat.
What are some advantages and disadvantages of signature based IDS?
Advantage: effective at detecting known threats
Disadvantage: ineffective at detecting unknown threats and variants on known threats
Disadvantage: cannot detect attacks that consist of multiple events
Disadvantage: cannot track and understand the state of complex communications