flâneur

Abusing Intrusion Detection | Computer Security

textbook.cs161.org · 659 words · saved by 1 readers

On a high level, network intrusion detection can be thought of as wiretapping on a bulk scale. The NSA utilizes various “off-the-shelf” concepts including using various Network Intrusion Detection Systems and Databases, malicious code, and hadoop. The NSA language is slightly different from the security language present in this class. The FISA (Foreign Intelligence Surveillance Act) Amendments Act section 702 states that if you are not a “US person”, meaning you are not a US citizen or permanent resident, and you are located outside of the United States, then the NSA can obtain all your information through a US provider. If you are either a US person or are located within the United States, however, you are afforded a lot of protection due to the United States Constitution The NSA is part of Five Eyes (FVEY), an intelligence alliance comprising of Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are parties to the multilateral UKUSA agreement,

On a high level, network intrusion detection can be thought of as wiretapping on a bulk scale. The NSA utilizes various “off-the-shelf” concepts including using various Network Intrusion Detection Systems and Databases, malicious code, and hadoop. The NSA language is slightly different from the security language present in this class. A selector in NSA parlance is a piece of information that identifies what you are looking for, like an email address, a phone number, etc. A fingerprint in NSA parlance is an intrusion detection match An implant is a malcode or another piece of sabotage…

saved by

related reading