Security Tehcnologies Flashcards
Firewall
Uses a set of rules defining the types of traffic permitted or denied through the device
Packet-Filtering Firewall
- Permits or denies traffic based on packet header
Stateful Firewall
Inspects traffic as part of a session and recognizes where the traffic originated
NextGen Firewall (NGFW)
- Third-generation firewall that conducts deep packet inspection and packet filtering
Access Control List(ACL)
Set of rules applied to router interfaces that permit or deny certain traffic
Firewall Zone
- Firewall interface in which you can set up rules
Inside
- Connects to corporate LAN
Outside
Connects to the Internet
Demilitarized Zone (DMZ)
- Connects to devices that should have restricted access from the outside zone (like web servers)
Unified Threat Management (UTM) Device
Combines firewall, router, intrusion detection/preventions system, anti-malware, and other features into a single device
Signature-Based Detection
Signature contains strings of bytes (a pattern) that triggers detection
Policy-Based Detections
Relies on specific declaration of the security policy
Statistical Anomaly-Based Detection
Watches traffic patterns to build baseline
Non-Statistical Anomaly-Based Detections
Administrator defines the patterns/baseline
Network-based (NIDS/NIPS)
- A network device protects entire network