By Edith Butler Fall 2008. Our Security Ways we protect our valuables: Locks Security Alarm Video Surveillance, etc.

Slides:



Advertisements
Similar presentations
Intrusion Detection System(IDS) Overview Manglers Gopal Paliwal Gopal Paliwal Roshni Zawar Roshni Zawar SenthilRaja Velu SenthilRaja Velu Sreevathsa Sathyanarayana.
Advertisements

Chapter 19: Computer and Network Security Techniques Business Data Communications, 6e.
1 Chapter 7 Intrusion Detection. 2 Objectives In this chapter, you will: Understand intrusion detection benefits and problems Learn about network intrusion.
Intrusion Detection Systems By: William Pinkerton and Sean Burnside.
Chapter 10: Data Centre and Network Security Proxies and Gateways * Firewalls * Virtual Private Network (VPN) * Security issues * * * * Objectives:
Building Your Own Firewall Chapter 10. Learning Objectives List and define the two categories of firewalls Explain why desktop firewalls are used Explain.
Guide to Network Defense and Countermeasures Second Edition
Security+ Guide to Network Security Fundamentals
N ETWORK S ECURITY Presented by: Brent Vignola. M ATERIAL OVERVIEW … Basic security components that exist in all networks Authentication Firewall Intrusion.
1.  To analyze and explain the IDS placement in network topology  To explain the relationship between honey pots and IDS  To explain, analyze and evaluate.
Intrusion Detection Systems and Practices
5/1/2006Sireesha/IDS1 Intrusion Detection Systems (A preliminary study) Sireesha Dasaraju CS526 - Advanced Internet Systems UCCS.
This work is supported by the National Science Foundation under Grant Number DUE Any opinions, findings and conclusions or recommendations expressed.
© 2006 Cisco Systems, Inc. All rights reserved. Implementing Secure Converged Wide Area Networks (ISCW) Module 6: Cisco IOS Threat Defense Features.
Lesson 13-Intrusion Detection. Overview Define the types of Intrusion Detection Systems (IDS). Set up an IDS. Manage an IDS. Understand intrusion prevention.
Kai, 2004 INSA1 The Evolution of Intrusion Detection Systems.
A survey of commercial tools for intrusion detection 1. Introduction 2. Systems analyzed 3. Methodology 4. Results 5. Conclusions Cao er Kai. INSA lab.
Security Overview. 2 Objectives Understand network security Understand security threat trends and their ramifications Understand the goals of network.
Host Intrusion Prevention Systems & Beyond
Lesson 5 Intrusion Detection Systems
Lecture 11 Intrusion Detection (cont)
Department Of Computer Engineering
Firewall Slides by John Rouda
INTRUSION DETECTION SYSTEM
Network Intrusion Detection Systems Slides by: MM Clements A Adekunle The University of Greenwich.
INTRUSION DETECTION SYSTEMS Tristan Walters Rayce West.
Intrusion Prevention, Detection & Response. IDS vs IPS IDS = Intrusion detection system IPS = intrusion prevention system.
Presented by Manager, MIS.  GRIDCo’s intentions for publishing an Acceptable Use Policy are not to impose restrictions that are contrary to GRIDCo’s.
CS426Fall 2010/Lecture 361 Computer Security CS 426 Lecture 36 Perimeter Defense and Firewalls.
1 Intrusion Detection Systems. 2 Intrusion Detection Intrusion is any use or attempted use of a system that exceeds authentication limits Intrusions are.
Information Systems CS-507 Lecture 40. Availability of tools and techniques on the Internet or as commercially available software that an intruder can.
Intrusion Detection Presentation : 1 OF n by Manish Mehta 01/24/03.
Intrusion Detection Chapter 12.
IDS – Intrusion Detection Systems. Overview  Concept  Concept : “An Intrusion Detection System is required to detect all types of malicious network.
Intrusion Detection Chapter 12.
IDS Intrusion Detection Systems CERT definition: A combination of hardware and software that monitors and collects system and network information and analyzes.
COEN 252 Computer Forensics Collecting Network-based Evidence.
1 Managed Premises Firewall. 2 Typical Business IT Security Challenges How do I protect all my locations from malicious intruders and malware? How can.
Intrusion Detection Prepared by: Mohammed Hussein Supervised by: Dr. Lo’ai Tawalbeh NYIT- winter 2007.
Guide to Network Defense and Countermeasures
HIPS Host-Based Intrusion Prevention System By Ali Adlavaran & Mahdi Mohamad Pour (M.A. Team) Life’s Live in Code Life.
Firewalls  Firewall sits between the corporate network and the Internet Prevents unauthorized access from the InternetPrevents unauthorized access from.
7.5 Intrusion Detection Systems Network Security / G.Steffen1.
Securing the Network Infrastructure. Firewalls Typically used to filter packets Designed to prevent malicious packets from entering the network or its.
Intrusion Detection System (IDS) Basics LTJG Lemuel S. Lawrence Presentation for IS Sept 2004.
Switch Features Most enterprise-capable switches have a number of features that make the switch attractive for large organizations. The following is a.
© 2006 Cisco Systems, Inc. All rights reserved. Implementing Secure Converged Wide Area Networks (ISCW) Module 6: Cisco IOS Threat Defense Features.
IT Security. What is Information Security? Information security describes efforts to protect computer and non computer equipment, facilities, data, and.
Cryptography and Network Security Sixth Edition by William Stallings.
Intrusion Detection Systems Paper written detailing importance of audit data in detecting misuse + user behavior 1984-SRI int’l develop method of.
I NTRUSION P REVENTION S YSTEM (IPS). O UTLINE Introduction Objectives IPS’s Detection methods Classifications IPS vs. IDS IPS vs. Firewall.
Network Security Terms. Perimeter is the fortified boundary of the network that might include the following aspects: 1.Border routers 2.Firewalls 3.IDSs.
Role Of Network IDS in Network Perimeter Defense.
IDS Intrusion Detection Systems CERT definition: A combination of hardware and software that monitors and collects system and network information and analyzes.
Regan Little. Definition Methods of Screening Types of Firewall Network-Level Firewalls Circuit-Level Firewalls Application-Level Firewalls Stateful Multi-Level.
Unit 2 Personal Cyber Security and Social Engineering Part 2.
Firewalls. Overview of Firewalls As the name implies, a firewall acts to provide secured access between two networks A firewall may be implemented as.
Some Great Open Source Intrusion Detection Systems (IDSs)
Intrusion Detection Systems Dj Gerena. What is an Intrusion Detection System Hardware and/or software Attempts to detect Intrusions Heuristics /Statistics.
25/09/ Firewall, IDS & IPS basics. Summary Firewalls Intrusion detection system Intrusion prevention system.
CompTIA Security+ Study Guide (SY0-401)
IDS Intrusion Detection Systems
CompTIA Security+ SY0-401 Real Exam Question Answer
NETWORKS Fall 2010.
Firewall – Survey Purpose of a Firewall Characteristic of a firewall
Firewalls.
CompTIA Security+ Study Guide (SY0-401)
By: Dr. Visavnath, Lecturer Comp. Engg. Deptt.
Intrusion Detection Systems (IDS)
By: Dr. Visavnath, Lecturer Comp. Engg. Deptt.
Presentation transcript:

By Edith Butler Fall 2008

Our Security Ways we protect our valuables: Locks Security Alarm Video Surveillance, etc.

History about IDS It began in 1980, with James Anderson's paper: Computer Security Threat Monitoring and SurveillanceComputer Security Threat Monitoring and Surveillance The setting of protocols in place to detect 1. Misuse 2. Or Malicious attacks in computer systems.

History of IDS Cont’d In 1983, Dr. Dorothy Denning and SRI International began working on a government project. In 1984, Dr. Denning assisted in the development of the Intrusion Detection Expert system which was the first model of IDS.

History about IDS continues…

WHAT IS IDS? IDS stands for Intrusion Detection System. 1. security countermeasure 2. Looks for signs of intruders. 3. Software and/or hardware designed

What is IDS? Cont’d Intrusion Detection System inspects all inbound and outbound network activity : 1. Computer system. 2. On-line transmissions 3. Private documents 4. Networks and overall privacy.

IDS FUNCTIONS Functions of IDS: “Monitoring users and system activity Auditing system configuration for vulnerabilities and misconfigurations Assessing the integrity of critical system and data files Recognizing known attack patterns in system activity. Identifying abnormal activity through statistical analysis Managing audit trails and highlighting user violation of policy or normal activity Correcting system configuration errors Installing and operating traps to record information about intruders

WHY IDS? To protect our network. From the outside environment Malicious attacks From the inside as well Possible manipulation, destruction, transferring, altering files or unintentionally mistakes.

TYPES OF ATTACK Some known attacks are: network attacks against vulnerable services. Data attacks on applications. Host based attacks such as : privilege escalation unauthorized logins access to sensitive files malware.

IDS COMPONENTS IDS Components: Sensors which generate security events. A console to monitor events and alerts, will also control the sensors. Central engine that records events logged by the sensors in a database and uses a system of rules to generate alert from security events that are encountered. Possible Sensors are: A sensor to monitor TCP connections requests. Log file Monitors File integrity Checker

TYPES OF IDS Two general types of intrusion detection systems are: 1. The host based intrusion system known as HIDS - 2. The network based intrusions systems (NIDS)

HIDS HIDS – Host based Intrusion Detection Systems Used within a local computer Analyzes the data entering and leaving within a workstation such as a desktop, server, and/or laptop HIDS works along with anti-threat applications : firewalls antivirus software spy ware-detection

HIDS CONT’D HIDS protects : Workstations and servers Used in conjunction with the operation system to catch any suspicious activity and block it from the system. HIDS monitors activities : Application or data requests Network Connection attempts Read or Write attempts. Audit System Logs

Diagram of HIDS

NETWORK BASED INTRUSION SYSTEM NIDS is used in conjunction with the LAN network. Anti-threat software is installed only at specific points: servers that interface between the outside environment and the network segment to be protected. can be a combination of standalone hardware or software that analyzes data packets that come in and out of the network. NIDS oversees and monitors the network traffic to detect any malicious activity or ensure the traffic is indeed valid.

Diagram of NIDS

NIDS VS HIDS Which one is better? No definite answer You really need both. one for your network NIDS one for your servers/workstations that is HIDS A proper IDS implementation should have: An environemnt that would filter alters and notification In addition to your firewall, NIDS/HIDS IDS technology will keep your environment secure from malicious virus and guard files that are highly sensitive. The difference between host-based and network-based intrusion detection is that NIDS deals with data transmitted from host to host while HID is concerned with what occurs on the hosts themselves.

IDS Statistics Just over 90% of interconnected networks that were running IDS detected computer security breaches in the last 12 months defiant of several implemented firewall protections that were installed. Computer Security Institute, 4/7/02 reported that 80% reported financial losses in excess of $455M was caused by intrusion and malicious acts thereafter. Millions of jobs have been affected because of intrusion Only 0.1% of companies are spending the appropriate budget on IDS. IDS are mostly misunderstood and are thought of as a firewall product or a substitute. If you use an antivirus then should also consider adding an IDS as a complimentary product to your security strategy. Most organizations using antivirus software do not use IDS.

TOP Computer Associate International's eTrust 2. Cisco Systems' Secure IDS 3. CyberSafe Corp.'s Centrax 4. Enterasys Networks' Dragon 5. Internet Security Systems' BlackICE 6. ISS' RealSecure 7. Intrusion.com's SecureNet Pro 8. NFR Security's NFR Network Intrusion Detection System 9. NFR Anzen Computing's Flight Jacket 10. the open-source Snort and 11. Symantec Corp.'s NetProwler