Module 12: IPS Operation and Implementation Flashcards
What is an IPS Signature?
Malicious traffic displays signatures
What are the 3 distinctive attributes for a IPS signature?
TTA
Type - Atomic or Composite
Trigger - Alarm
Action - What the IPS will do
What is a Atomic Signature?
Simplest type - can just be 1 packet
What is a Composite Signature
Stateful signature - several pieces of data
What are the four alert classifications
True positive (desirable) True negative (desirable) False positive (undesirable) False negative (dangerous)
What is Snort?
A open source network IPS
What 2 components make up Snort?
Snort Engine
Snort rule software
What are the 2 types of Snort Rule Sets?
Community Rule Set - free
Subscriber Rule Set - paid
What are the 3 Snort IDS Actions (ALP)
Alert
Log
Pass
What are the 3 Snort IPS Actions
Drop
Reject - block and log
Sdrop - block dont log
What 2 interfaces does Snort run on?
Management Interface
Data Interface
What is the Snort Management Interface?
this is the interface used to sourced logs and for retrieving signature updates.
What is the Snort Data Interface
This is the interface that is used to send user traffic between the Snort virtual container service and the router forwarding plane.
What is threat protection mode with Snort?
Snort will be in IPS mode
What is threat detection mode with Snort
Snort will be in IDS mode