News, learn, share and discuss about Africa & other life issues with over 250, 000 members worldwide & thousands of discussion going on. CLICK HERE TO JOIN FREE and get access to write, reply, use private message & much more free!. CLICK HERE TO SAY HELLO
AfricaTopForum
May 25, 2012, 03:07:00 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
 
   Home   Help Rules Search Login Register  
Pages: [1]   Go Down
  Send this topic  |  Print  
Author Topic: What are Intrusion Detection Systems?  (Read 326 times)
0 Members and 1 Guest are viewing this topic.
Perfect
Administrator
*****
Online Online

Gender: Male
Posts: 6035



Activity
7%



« on: October 01, 2009, 04:57:41 AM »
ReplyReply



Intrusion Detection System (IDS) are a necessary part of any strategy for enterprise security. What are Intrusion Detection systems?  CERIAS, The Center for Education and Research in Information Assurance and Security, defines it this way: 

“The purpose of an intrusion detection system (or IDS) is to detect unauthorized access or misuse of a computer system. Intrusion detection systems are kind of like burglar alarms for computers. They sound alarms and sometimes even take corrective action when an intruder or abuser is detected. Many different intrusion detection systems have been developed but the detection schemes generally fall into one of two categories, anomaly detection or misuse detection. Anomaly detectors look for behavior that deviates from normal system use. Misuse detectors look for behavior that matches a known attack scenario. A great deal of time and effort has been invested in intrusion detection, and this list provides links to many sites that discuss some of these efforts”(http://www.cerias.purdue.edu/about/history/coast_resources/intrusion_detection/)

There is a sub-category of intrusion detection systems called network intrusion detection systems (NIDS).  These systems monitors packets on the network wire and looks for suspicious activity. Network intrusion detection systems can monitor many computers at a time over a network, while other intrusion detection systems may monitor only one.

Who is breaking into your system?

 

One common misconception of software hackers is that it is usually people outside your network who break into your systems and cause mayhem.  The reality, especially for corporate workers, is that insiders can and usually do cause the majority of security breaches. Insiders often impersonate people with more privileges then themselves to gain access to sensitive information.

How do intruders break into your system?

 

The simplest and easiest way to break in is to let someone have physical access to a system.  Despite the best of efforts, it is often impossible to stop someone once they have physical access to a machine. Also, if someone has an account on a system already, at a low permission level, another way to break in is to use tricks of the trade to be granted higher-level privileges through holes in your system. Finally, there are many ways to gain access to systems even if one is working remotely. Remote intrusion techniques have become harder and more complex to fight.

 

How does one stop intrusions?

 

 

There are several Freeware/shareware Intrusion Detection Systems as well as commercial intrusion detection systems. 

Open Source Intrusion Detection Systems

Below are a few of the open source intrusion detection systems:

AIDE (http://sourceforge.net/projects/aide) Self-described as “AIDE (Advanced Intrusion Detection Environment) is a free replacement for Tripwire. It does the same things as the semi-free Tripwire and more.  There are other free replacements available so why build a new one? All the other replacements do not achieve the level of Tripwire. And I wanted a program that would exceed the limitations of Tripwire.”

File System Saint  (http://sourceforge.net/projects/fss) - Self-described as, “File System Saint is a lightweight host-based intrusion detection system with primary focus on speed and ease of use.” 

 

Snort  (www.snort.org) Self-described as “Snort® is an open source network intrusion prevention and detection system utilizing a rule-driven language, which combines the benefits of signature, protocol and anomaly based inspection methods. With millions of downloads to date, Snort is the most widely deployed intrusion detection and prevention technology worldwide and has become the de facto standard for the industry.”

Commercial Intrusion Detection Systems

 

If you are looking for Commercial Intrusion Detection Systems, here are a few of these as well:

Tripwirehttp://www.tripwire.com

Touch Technology Inc (POLYCENTER Security Intrusion Detector)Http://www.ttinet.com

Internet Security Systems (Real Secure Server Sensor)http://www.iss.net

 

eEye Digital Security (SecureIIS Web Server Protection)http://www.eeye.com
Logged
AfricaTopForum
   

 Logged
Pages: [1]   Go Up
  Send this topic  |  Print  
 
Jump to:  


Related Topics
Subject Started by Replies Views Last post
Metal Detecting Information and The Best Metal Detection Tips
GENERAL CHATS ROOM BOARD
CrypepaypeCak 0 200 Last post August 05, 2010, 04:14:50 AM
by CrypepaypeCak
A Look at DVD Shrink Wrap Systems
COMPUTERS and HARDWARES DISCUSSION BOARD
Perfect 0 163 Last post March 28, 2011, 03:53:02 AM
by Perfect
Alarm Systems
COMPUTERS and HARDWARES DISCUSSION BOARD
Perfect 0 164 Last post April 01, 2011, 04:11:14 AM
by Perfect
Driver - International Foundation for Electoral Systems
MINOR JOBS VACANCIES POSTING BOARD
jobcrawler 0 107 Last post November 04, 2011, 03:53:49 AM
by jobcrawler
Intrusion Prevention - IT Risk Management
SOFTWARE and PROGRAMMING DISCUSSION BOARD
Webmaster 0 84 Last post April 26, 2012, 10:40:41 PM
by Webmaster

If you require any help or if you have any questions, challenges, comments, suggestions or criticism please don’t hesitate Click here to write,
if it is sensitive send Personal Message to Global Captain or Admin. We love to hear from members and general public.

Contact |African Discussion Forum | Powered by SMF | SMF © 2006-2011, Simple Machines