IPS & IDS Concepts Flashcards
Intrusion Detection Systems (IDS)
A monitoring system capable of detecting malicious traffic and generating alerts
Intrusion Prevention System (IPS)
Enhanced IDS that can not only detect malicious traffic, but block it as well
What’s the best location for IDS deployment
SPAN port
What’s the best location for IPS deployment
gateway or proxy
Snort
An open-source IDS maintained by Cisco, that is capable of advanced traffic analysis
Suricata
An advances IDS & IPS capable of offline PCAP processing and various output formats. Uses rules, alerts and logs for configuration
Firewall
inspects packets based on IPs, ports, source, and destination
IPS/IDS
Inspects packets based on their content and signatures
Anomaly vs Protocol Detection
Anomaly: Searches for irregular protocols on the network
Protocol: searches protocols that do not use encryption
False Positives
Legitimate packages identified as threats. Misconfigured rules and environments
Barynard2
is a popular spooler used for both snort and suricata. Barnyard can reduce workload by performing data parsing
What does an Analyst do?
- Reviews trigger alerts
- Investigates the cause of an alert
- Determines if an alert is a false positive
- Improves rules and detection processes