Module 11: IDS and IPS Technologies Flashcards
What is IPS?
Intrusion protection system this can actively stop a attack
What is IDS
Intrusion detection system it passively monitors the traffic
What is a Zero Day attack
A attack in which the user has had 0 time or days to prepare for. a new unknown hack
What are the 2 kind of IPS implementations
NIPS AND HIPS
What is HIPS?
Hardware IPS - windows defender
What is NIPS
Network IPS - usually a router or firewall config
What 3 components must a NIPS have
NIC, a processor and memory
What are the 2 modes of deployment for a IPS or IDS sensor?
Inline mode or promiscuous mode
What is IPS detection and enforcement engine ?
the detection engine compares incoming traffic with known attack signatures that are included in the IPS attack signature package.
What is IPS attack signatures package ?
This is a list of known attack signatures that are contained in one file which can be frequently updated
What series router can SNORT run on?
the Cisco 4000 series
How does SNORT run in a router?
In a virtual service container which is a VM that runs on the router itself