Chapter 9 Flashcards

1
Q

Intrusion detection system (IDS) vs Intrusion prevention system (IPS)

A

IDS:
A passive system that identifies dangerous or suspicious traffic, it sends alerts but leaves the action to IPS.

IPS:
able to actively block or prevent intrusions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The IDPS process:

A

1- Inspection and investigation: analyzing suspicious packets.
2- Action: packets are dropped.
3- Log/report attack.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

2 types of of IDPS:

A

1- Network-based IDPS (NIDPS): monitors activity in an organization’s network.

2- Host-based IDPS (HIDPS): monitors activity only on a host (computer or server).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Advantages of Network-based IDPS (NIDPS):

A
  • Can enable an organization to monitor a large network with few devices.
  • is passive and causes little disruption.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Disadvantages of Network-based IDPS (NIDPS):

A
  • Require access to all traffic to be monitored.
  • Cannot analyze encrypted packets.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Advantages of Host-based IDPS (HIDPS):

A
  • Can access encrypted information and make decisions about attacks.
  • Can detect local events on host systems
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Disadvantages of Host-based IDPS (HIDPS):

A
  • Can use large amounts of disk space.
  • Does not detect multi-host scanning.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

2 IDPS Detection Methods:

A

1- Signature-based detection: detects known attack signatures.

2- Anomaly-based detection: detects abnormal activity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly