Font size
WorksheetsIDS IPS
Total questions: 18
Worksheet time: 9mins
An Intrusion Detection System (IDS) .....
can be configured to allow the intruder IP when an alert is generated
opening the network connection for an active and passive attack
inspects network activities and identifies suspicious patterns that may indicate a network attack
an identifier for the correct usage of particular computer or total network
Looks for specific network patterns generate by known malware.
Signature based
Host intrusion detection system (HIDS)
Anomaly based
Security functionality
Proactive monitoring of unwanted intruders e.g. firewall.
Intrusion prevention system
Fuzzing
Signature based
Network intrusion detection system (NIDS)
Monitors inbound and outbound traffic to identify suspicious traffic.
Network intrusion detection system (NIDS)
Distributed intrusion detection system (DIDS)
Host intrusion detection system (HIDS)
Intrusion prevention system
Multiple detection systems across a network communicating together to give a better picture of network activity.
Distributed intrusion detection system (DIDS)
Host intrusion detection system (HIDS)
Intrusion detection system (IDS)
Network intrusion detection system (NIDS)
Firewalls, antivirus and anti spyware installed on every machine that monitors all incoming and outgoing traffic for suspicious activities
Host intrusion detection system (HIDS)
Distributed intrusion detection system (DIDS)
Intrusion detection system (IDS)
Network intrusion detection system (NIDS)
Goals of IDS
Mobility and allow for a stable connection
Take action and allowing an attack to the network
Identify abnormal behaviour of network or misuse of resources
Different ways to transmit data securely and safely
Which of the following is NOT an IDS characteristics?
IDS can overlook system errors
Survives with system crash and must be fault tolerant
Runs constantly without human supervision
Adaptability of system with technologies
Which of the following is NOT a type of IDS?
Network-based IDS
Dictionary-based IDS
Host-based IDS
Protocol IDS
Consist of sensor and console
Network-based IDS (NIDS)
Host-based IDS (HIDS)
Protocol IDS (PIDS)
Distributed IDS (DIDS)
Consists of agents and consoles.
Network-based IDS (NIDS)
Host-based IDS (HIDS)
Protocol IDS (PIDS)
Distributed IDS (DIDS)
What type of NIDS architecture shown below?
Distributed Network Node
Traditional Sensor-based Architecture
What type of NIDS architecture shown below?
Distributed Network Node
Traditional Sensor-based Architecture
What type of HIDS architecture shown below?
Centralized Host-Based
Traditional Sensor-based Architecture
Which of the following is a DISADVANTAGE of Host- based IDS?
Detect broad range of decision support threats
Maintenance is difficult due to distributed agents
monitor the data on the system by collect and analyse data, aggregating it to be analysed
No requirement of dedicated hardware
Which of the following is NOT the component of Distributed IDS?
Central analysis server
Attack aggregation
Monitoring server
Co-operative agent network
Which of the following is NOT a components of Prelude IDS?
Managers
Signatures
Frontends
Sensors
Choose from the following TWO (2) EXAMPLE of NIDS tools for Windows.
Nessus
Snort
Suricata
RootkitRevealer
