Ids and ips overview

Assignment Help Computer Network Security
Reference no: EM13819803

In this lab, you will explore at least one IDS, IPS, or Honeypot currently offered by product vendors and cloud service providers. You will be making a security recommendation, related to the protection of a target network of your choice.
There are a few different paths you may take in this lab, so let's address some of the distinguishing features and definitions that are out there.

IDS and IPS Overview

• An intrusion detection system (IDS) generally detects and logs known intrusions or anomalous network activity. Generally, no real-time protection actually occurs, therefore false-positives create little or no damage. Optionally, suspicious network traffic can be routed to an alternate network, such as a honeypot.

• An intrusion protection system (IPS) generally detects, logs, and then blocks known intrusions or anomalous network activity. False-positives are an issue and will result in a self-inflicted denial of service condition. Optionally, suspicious network traffic can be routed to an alternate network, such as a honeypot.

Honeypot Overview

• Honeypots come in several broad categories. The most common labels we apply to them are research honeypots, active honeypots, and offensive honeypots. They are designed to do what their label suggests, and here is a brief summary.
Note: Seek qualified legal advice before deploying any type of honeypot.

• Research honeypots generally collect and analyze data about the attacks against a decoy-network. They can also route the attacker to new decoy-networks, to gather more details about the potential attacks. The data gathered are used to understand the attacks and strengthen the potential target networks.

• Active honeypots have many of the features found in a research honeypot, but they also hold special content that, once taken by the attackers, can be used as evidence by investigators and law enforcement. For example, active honeypots may have database servers containing a fake bank account or credit card information.

• Offensive honeypots are configured with many of the features of the active honeypots, with one interesting and dangerous addition: they are designed to damage the attacker. When used outside of your own network, this type of honeypot can result in vigilantism, attacks against false-targets, and may result in criminal charges against the honeypot operators. Offensive honeypots are not recommended for non-law-enforcement organizations. However, when used fully within your own network, this technique can detect and neutralize the attacker.

Any of the above services can be implemented on a privately managed network, or through a cloud service. The selection of one platform over another will generally determine where the specific protection occurs-on your network or in the cloud.

The reason for this lab is to give you an understanding of how special network technology can be used as a security research tool, while also providing varying degrees of protection.

Deliverables

Document Authoring Guidelines

Each section will vary in size based on the requirements. Drive yourself to create a useful document for the direction you have selected.

Lab Document Framework

• The Target Network: Indicate the type of activities and data that it supports in a few sentences. For example, it is the website for an educational institution that holds personal academic and financial information, or it is the network used to control devices in a chemical plant. Use your imagination, but select something that is real and meaningful to you.

• The Protection System: Select one from the presented list (Step 2), or choose your own protection technology, if it is highly relevant.

• The Body of the Management Briefing Document: See the guidance in Step 3. It is generally about 4 to 10 paragraphs.

• Citations and Resources Used in this Report: Tell us where you received external guidance and ideas. If you have presented original ideas, then give yourself credit, and tell us why you believe it is correct.

Delivering Your Lab Document

Organize your materials into a single comprehensive document. Name your document(s) such that the course ID, your full name, and this lab's name are referenced. For example, include SEC572_FirstName_LastName_Lab4 in the file's name. Your document must be readable with Microsoft Word 2007(or prior) or a standard PDF file viewer.

Submit your assignment to the Week 4 Dropbox located on the silver tab at the top of this page. (See the Syllabus section "Due Dates for Assignments & Exams" for due date information.)

Use the Dropbox comment area to give your instructor an introduction, or state any special information.

Required Software

iLAB STEPS

Step 1

Back to Top

Broadly outline the target network. Indicate the type of activities and data that it supports in a few sentences.

Step 2

Back to Top

Select the protection system. Choose from one of the following.

• Intrusion detection system (IDS)

• Intrusion protection system (IPS)

• Research honeypot

• Active honeypot

• Offensive honeypot

Step 3

Back to Top

Create a management briefing document that will inform senior decision makers about their options, vendors, products, relevant

examples, and issues associated with your selected protection (from Step 2). If cost can be identified, then please include that information as well. It is generally about 4 to 10 paragraphs.

Suggested Resources

Back to Top

Your textbook and other related textbooks

The DeVry Online Library

Professional Journals and Security Website

News Media Releases

Security Vendor and Contributor Websites (See the examples below, but be aware that URLs do change without notice.)

Reference no: EM13819803

Questions Cloud

The division of labor within a police department : Question 1 The __________ unit provides support to minors, including advice and referral services. juvenile services traffic services patrol services administrative services 4 points Question 2 In the present day, most probationary periods in a polic..
Warm front is approaching from the south : If a warm front is approaching from the south, has a slope of 1:300 and is moving toward you at an average warm-front speed of about 4.9 km/hour, how long will it take before it passes your area?
Types of abs for the committee consideration : Your task is to make a presentation of 600-800 words to the committee explaining the different types of ABS for the committee's consideration. The presentation must include the following:
How to convert kilo pascal to psi ?measure units : How to convert  kilo pascal to psi ?measure units  How to convert  52 kilo pascal to psi ?measure units
Ids and ips overview : IDS and IPS Overview
Modeled with a linear inequality : Think of a situation that can be modeled with a linear inequality. This must be a situation where more than one possible solution is acceptable. Describe your situation and why more than one solution is possible. Write an inequality to model the situ..
Examine the broad environmental trends : Write a Start the report with a brief introduction of what you intend to discuss above.Following the introduction, examine the broad environmental trends within which the two companies operate. Also focus on the stage of the industry (embryonic, grow..
What is the characteristic polynomial of a : dim(ker(A-3I)^2)=4 dim(ker(A-3I)^3)=5 What is the characteristic polynomial of A? what is the minimal polynomial of A?
Linear programming case study : It will be a problem with at least three (3) constraints and at least two (2) decision variables. The problem will be bounded and feasible. It will also have a single optimum solution (in other words, it won't have alternate optimal solutions).

Reviews

Write a Review

Computer Network Security Questions & Answers

  An overview of wireless lan security - term paper

Computer Science or Information Technology deals with Wireless LAN Security. Wireless LAN Security is gaining importance in the recent times. This report talks about how vulnerable are wireless LAN networks without any security measures and also talk..

  Computer networks and security against hackers

This case study about a company named Magna International, a Canada based global supplier of automotive components, modules and systems. Along with the company analysis have been made in this assignment.

  New attack models

The Internet evolution is and is very fast and the Internet exposes the connected computers to attacks and the subsequent losses are in rise.

  Islamic Calligraphy

Islamic calligraphy or Arabic calligraphy is a primary form of art for Islamic visual expression and creativity.

  A comprehensive study about web-based email implementation

Conduct a comprehensive study about web-based email implementation in gmail. Optionally, you may use sniffer like wireshark or your choice to analyze the communication traffic.

  Retention policy and litigation hold notices

The purpose of this project is to provide you with an opportunity to create a document retention policy. You will also learn how to serve a litigation hold notice for an educational institute.

  Tools to enhance password protection

A report on Tools to enhance Password Protection.

  Analyse security procedures

Analyse security procedures

  Write a report on denial of service

Write a report on DENIAL OF SERVICE (DoS).

  Phising email

Phising email It is multipart, what are the two parts? The HTML part, is it inviting the recepient to click somewhere? What is the email proporting to do when the link is clicked?

  Express the shannon-hartley capacity theorem

Express the Shannon-Hartley capacity theorem in terms of where is the Energy/bit and is the psd of white noise.

  Modern symmetric encryption schemes

Pseudo-random generators, pseudo-random functions and pseudo-random permutations

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd