Intrusion detection
by ac3 - Security Lab - Wednesday, 11 June 2003.
Bookmark and Share
Knowledge based systems use signatures about attacks to detect instances of these attacks. Knowledge based systems is the most-used IDS model. Signatures are patterns that identify attacks by checking various options in the packet, like source address, destination address, source and destination ports, flags, payload and other options. The collection of these signatures composes a knowledge base that is used by the IDS to compare all packet options that pass by and check if they match a known pattern. Signatures have the same limitations as a patch - it is not possible to write the signature until the hack has materialized.

Behavioral IDS

Behavior based systems use a reference rule of normal behavior and flag deviations from this model as anomalous and potentially intrusive. A behavioral rule aims to define a profile of legitimate activity. Any activity that does not match the profile, including new types of attack, is considered anomalous. As rules are not specific to a particular type of attack, forensic information is not normally very detailed. However, rules can identify malicious behavior without having to recognize the specific attack used. This approach offers unparalleled protection against new attacks ahead of any knowledge being available in the security community. The disadvantage of this model is that it may cause a high number of false-positive alerts.

Quick Terms


-False positive: A report of an attack or attempted attack when no vulnerability existed or no compromise occurred.

-False negative: The failure of an IDS to report an instance in which an attacker successfully compromises a host or network.

-Sensor: The computer that monitors the network for intrusion attempts. Sensors usually run in promiscuous mode, often without an IP address.

Useful Links & References

http://www-rnks.informatik.tu-cottbus.de - Intrusion Detection Systems List

http://www.securityfocus.com - Introduction to Intrusion Detection Systems

http://www.lids.org - Linux Intrusion Detection System

http://www.snort.org - The Open Source Network Intrusion Detection System

http://www.sans.org/resources/idfaq/ - Intrusion Detection FAQ

Spotlight

Cyber espionage campaign uses professionally-made malware

Posted on 20 May 2013.  |  A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.


Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 
DON'T
MISS

Tue, May 21st
    COPYRIGHT 1998-2013 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //