NB Productions  Your guide on the Web since 2000
 
Spread The Word!

Bookmark and Share

 Subscrib 

 Follow nbproductioncom on Twitter

Navigation
· Home
· Advertising
· Archive
· Articles
· AvantGo
· Downloads
· Encyclopedia
· FAQ
· Forums
· Knowledge Base
· Latest News
· Legal
· Reviews
· Search
· Statistics
· Syndicate
· Topics
· Tutorials
· Web Links
Translator
Select Interface Language:

Affiliates

Smoke09

squarebody.com

Referrals 

 Rogue Gallery

Windows 7 Home Page

Vista Home Page

Microsoft : Fast Facts

 Microsoft Fix It

Game On

Microsoft Store

Spyware Database
·Bankem
·NetPumper 1.2
·YIM-Flood
·Muquest
·Arape.a
·Trojan.Zlob
·FTP99cmp
·VXgame
·LotusHlp
·Backdoor.ahj
 

read more...©
Music Artist


1· AC / DC
· Cliff Adams
· Tori Amos
· The Beatles
· Chuck Berry
· Bon Jovi
· Kate Bush
· Clannad
· Eric Clapton
10 · Clark Hutchinson
11 · Joe Cocker
12 · The Corrs
13 · The Cranberries
15 · Deep Purple
16 · Diamond Rio
17 · The Doors
18 · Steve Earle
19 · Fleetwood Mac
20 · Free
21 · Peter Gabriel
22 · Rory Gallagher
23 · Genesis
24 · Goo Goo Dolls
25 · David Gray
26 · Guns''n''Roses
27 ·  Alex Harvey Band
28 · Jimi Hendrix
29 · John Lee Hooker
30 · Humble Pie
31 · Michael Jackson
32 · Janis Joplin
33 · Norah Jones
34 · B. B. King
35 · Jerry Lee Lewis
36 · Amanda Marshall
37 · Matchbox 20
38 · Nine below zero
39 · Sin?ad O''Connor
40 · Pink Floyd
41 · Elvis Presley
42 · Carlos Santana
43 · Dan Seals
44 · Steely Dan
45 · Steppenwolf
46 · The Rolling Stones
47 · U2
48 · Uriah Heep
49 · Neil Young
50 · Led Zeppelin
51 · ZZ Top

Examining Different Types of Intrusion Detection Systems

Windows Vista & Xp




this defined as real-time monitoring and analysis of network activity and data for potential vulnerabilities and attacks in progress. One major limitation of current intrusion detection system (IDS) technologies is the requirement to filter false alarms lest the operator (system or security administrator) be overwhelmed with data. IDSes are classified in many different ways, including active and passive, network-based and host-based, and knowledge-based and behavior-based:

Active and passive IDS
An active IDS (now more commonly known as an intrusion prevention system — IPS) is a system that's configured to automatically block suspected attacks in progress without any intervention required by an operator. IPS has the advantage of providing real-time corrective action in response to an attack but has many disadvantages as well. An IPS must be placed in-line along a network boundary; thus, the IPS itself is susceptible to attack. Also, if false alarms and legitimate traffic haven't been properly identified and filtered, authorized users and applications may be improperly denied access. Finally, the IPS itself may be used to effect a Denial of Service (DoS) attack by intentionally flooding the system with alarms that cause it to block connections until no connections or bandwidth are available.

A passive IDS is a system that's configured only to monitor and analyze network traffic activity and alert an operator to potential vulnerabilities and attacks. It isn't capable of performing any protective or corrective functions on its own. The major advantages of passive IDSes are that these systems can be easily and rapidly deployed and are not normally susceptible to attack themselves.

Network-based and host-based IDS
A network-based IDS usually consists of a network appliance (or sensor) with a Network Interface Card (NIC) operating in promiscuous mode and a separate management interface. The IDS is placed along a network segment or boundary and monitors all traffic on that segment.

A host-based IDS requires small programs (or agents) to be installed on individual systems to be monitored. The agents monitor the operating system and write data to log files and/or trigger alarms. A host-based IDS can only monitor the individual host systems on which the agents are installed; it doesn't monitor the entire network.

Knowledge-based and behavior-based IDS
A knowledge-based (or signature-based) IDS references a database of previous attack profiles and known system vulnerabilities to identify active intrusion attempts. Knowledge-based IDS is currently more common than behavior-based IDS. Advantages of knowledge-based systems include the following:

•It has lower false alarm rates than behavior-based IDS.
•Alarms are more standardized and more easily understood than behavior-based IDS.
Disadvantages of knowledge-based systems include these:

•Signature database must be continually updated and maintained.
•New, unique, or original attacks may not be detected or may be improperly classified.
A behavior-based (or statistical anomaly–based) IDS references a baseline or learned pattern of normal system activity to identify active intrusion attempts. Deviations from this baseline or pattern cause an alarm to be triggered. Advantages of behavior-based systems include that they

•Dynamically adapt to new, unique, or original attacks.
•Are less dependent on identifying specific operating system vulnerabilities.
Disadvantages of behavior-based systems include

•Higher false alarm rates than knowledge-based IDSes.
•Usage patterns that may change often and may not be static enough to implement an effective behavior-based IDS.


 



Copyright © by NB Productions Your guide on the Web since 2000 All Rights Reserved.

Published on: 2010-04-19 (113 reads)

[ Go Back ]

 Back to the top 



 ©  nb-productions.com 2000-2010


:: fiappleblue theme by www.nukemods.com ::