Intrusion Detection Flashcards

1
Q

What is a definition for an intrusion detection system?

A

An intrusion detection system (IDS) is an additional component to protect a system during operation. The IDS monitors selected aspects of the system’s behavior and raises an alarm if it observes suspicious behavior.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 5 relevant aspects for an IDS?

A
  • Time and Resources
  • Location and Connection
  • Intrusion and Suspiciousness
  • Model Complexity and Observed Data
  • Response to an alarm
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What different approaches are there regarding Time and Resources? What are the trade-offs?

A
  • monitor during runtime
  • monitor post mortem (asynchrounously)

challenges, trade-offs:

  • higher value from detecting attacks?
  • is detection fast enough? does it scale?
  • is a full analysis of all observed events necessary?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What different approaches are there regarding Location and Connection? What are the trade-offs?

A
  • host-based monitoring
  • network-based monitoring

challenges, trade-offs:

  • depends on architecture of monitored system
  • depends on availability of monitored information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What different approaches are there regarding Intrusion and Suspiciousness?

A
  • signature based: explicit rules or stochastic profiles
  • anomaly based: aberrations from defined normal behavior
  • hybrids
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What different approaches are there regarding Model Complexity and Observed Data?

A
  • rule-based
  • statistical model
  • machine learning
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What different approaches are there regarding Response to an alarm?

A
  • Security information and event management (SIEM): central collection and management of incident reports
  • Intrusion detection and prevention systems (IDPS): immediate reaction in the monitored system
How well did you know this?
1
Not at all
2
3
4
5
Perfectly