Intrusion Detection | Computer Security
In this class, we’ve talked about many ways to prevent attacks, but not all defenses are perfect, and attacks will often slip through our defenses. How do we detect these attacks when they happen? Imagine that you’re managing a local network of computers (for example, all the web servers and employee computers in a company’s office building). The local network is connected to the Internet with a router (recall that all requests from the local network to the wider Internet will pass through this router). How can we detect attacks on this network? There are three broad types of detectors. The main difference in implementation is where on the network these detectors are installed. Each type of detector has its advantages and drawbacks. A NIDS (network intrusion detection system) is installed between the router and the internal network. This means that all requests to and from the outside Internet must pass through the NIDS. The NIDS can see (and potentially modify) all packets sent to the
Intrusion Detection | Computer Security Skip to main content Menu Expand (external link) Document Search Copy Copied Computer Security 36. Intrusion Detection In this class, we’ve talked about many ways to prevent attacks, but not all defenses are perfect, and attacks will often slip through our defenses. How do we detect these attacks when they happen? Imagine that you’re managing a local network of computers (for example, all the web servers and employee computers in a company’s office building). The local network is connected to the Internet with a router (recall that all requests from the
Explore this link on the map →saved by
related reading
- Firewalls | Computer Securitytextbook.cs161.org
- Malware | Computer Securitytextbook.cs161.org
- Honeypot (computing) - Wikipediaen.wikipedia.org
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Shifting detection left for more effective threat detectionpushsecurity.com
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Lessons learned from EDR Bypass threat hunting | by Cristóbal Martínez | Mediummedium.com
- Want Better Cloud Security? Make Your Detections Multi-Dimensionalomeronsecurity.com
- Detection Spectrum - SpecterOpsposts.specterops.io
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Bad Idea: Deterrence by Detection | Defense360defense360.csis.org
- You Cannot Escape Me: Detecting Evasions of SIEM Rules in Enterprise Networks | USENIXusenix.org