8 - Firewall/Intrusion Flashcards

1
Q

Packet filtering vs stateful inspection

A

Stateful tightens rules for TCP traffic by creating directory of TCP connections

Records information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Anomaly detection vs misuse detection

A

Anomaly detection - collect data on users, determine if new behavior is consistent, not as widely used

Misuse detection - identify malware that has patterns we know

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Firewall deployments

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Base rate fallacy

A

Can’t ignore probability of no attack when there is an alert

There is a normal amount of alerts in steady state

How well did you know this?
1
Not at all
2
3
4
5
Perfectly