Prepare a report that address various system irregularities

Assignment Help Computer Engineering
Reference no: EM131943896

Assignment: LASA: Analysis of an Intrusion Detection System Report

This assignment builds upon the scenario introduced in LASA 1, from the organization Open Water Diving and Scuba Institute (OWDSI). Specifically, your focus will be on preparing a second supplemental report of approximately 8-10 pages that discusses the organization's intrusion detection system (IDS) and some of the recent reports from this system.

Scenario:

OWDSI's network engineers and system administrators have reported a number of strange network behaviors and system outages. A variety of traffic has been captured in response to this. In addition, network engineers report that the school is seeing very high levels of traffic from a wide variety of hosts and that this traffic is causing outages of the school's public-facing web server and other internal computer systems.

Management has requested that you review the network traffic to determine whether the institution's IDS and intrusion prevention systems (IPSs) can be used to prevent inbound attacks that are being detected. Your manager has requested that you analyze the detected attacks and create a report that describes each attack. Explain the threat it presents and whether the use of an IDS or an IPS is a suitable response.

The following is a compiled list of odd network behaviors reported by network engineers and system administrators of OWDSI:

1. Network traffic analysis shows that a single host is opening hundreds of secure shell (SSH) sessions to a single host every minute.

2. Network traffic shows that hundreds of hosts are constantly sending only synchronized (SYN) packets to a single web server on campus.

3. A system administrator reports that a single host is attempting to log on to a campus SSH server using different user name and password combinations thousands of times per day.

4. A new PDF-based exploit is announced that uses a malformed PDF to exploit Microsoft Windows XP systems.

5. Campus users are receiving e-mails claiming to be from the campus helpdesk. The e-mails ask for users to send their user names and passwords to retain access to their e-mails.

6. A domain name system (DNS) changer malware package has been located on one of the servers.

7. A JavaScript vulnerability is being used to exploit browsers via ad networks on major news sites, resulting in systems being infected with malware.

8. A zero-day vulnerability has been announced on the primary campus backup software's remote administration interface.

9. A virus is being sent via e-mail to campus users.

Tasks:

In a Microsoft Word document, prepare an 8- to 10-page report that addresses the various system irregularities. Your report should consist of the following:

• A cover page

• A table of contents

• An executive summary

o Develop an overview of the organization's key system issues and your recommended remedies

• System irregularities

o Identify and describe each attack listed
o Include an explanation of what each attack is trying to accomplish

• Analysis and recommendations

o Discuss how each of the vulnerabilities could be a potential issue and what the symptoms of each include

o Recommend how to address each of the nine odd network behaviors as described in the assignment scenario above. Justify your responses

o Determine whether an IDS could or should be used to detect each attack and whether each should be blocked using an IPS. Justify your responses

• References

Note: Utilize at least three scholarly or professional sources (beyond your textbook) in your paper. Your paper should be written in a clear, concise, and organized manner; demonstrate ethical scholarship in accurate representation and attribution of sources (i.e., in APA format); and display accurate spelling, grammar, and punctuation.

Reference no: EM131943896

Questions Cloud

Values of the empowerment theory : Summarize the underlying principles and values of the Empowerment theory.
How you used the knowledge gained in the cryptography : How you used the knowledge gained in the Cryptography and physical security courses and also how you applied the principles in your intern(or at work).
Pace of organizational change : Comment on the types of technology, the pace of technological advancement, and the factors that have affected the pace of organizational change during this time
Write a paper about preferences for car choices in us : Write a paper of around 100 to 200 words about "preferences for car choices in United States"(citations are required)?
Prepare a report that address various system irregularities : In a Microsoft Word document, prepare an 8- to 10-page report that addresses the various system irregularities.
How should you not report computer crime : INFA 640 Cryptography and Data Protection - What piece of legislation allows computer records documenting criminal activity to be used in court
Determining the behavior and learning : When answering the question, be sure to address how an individual in a high-crime vs a low-crime area would learn through operant conditioning.
Discuss the types of psychometric assessments : What types of psychometric assessments (e.g., personality inventories, cognitive assessments, and integrity tests) are best to identify applicants.
Keeping a game window open : Lamont often keeps a game window open when he is doing classwork on his computer so that he can quickly navigate to the game whenever

Reviews

Write a Review

Computer Engineering Questions & Answers

  Mathematics in computing

Binary search tree, and postorder and preorder traversal Determine the shortest path in Graph

  Ict governance

ICT is defined as the term of Information and communication technologies, it is diverse set of technical tools and resources used by the government agencies to communicate and produce, circulate, store, and manage all information.

  Implementation of memory management

Assignment covers the following eight topics and explore the implementation of memory management, processes and threads.

  Realize business and organizational data storage

Realize business and organizational data storage and fast access times are much more important than they have ever been. Compare and contrast magnetic tapes, magnetic disks, optical discs

  What is the protocol overhead

What are the advantages of using a compiled language over an interpreted one? Under what circumstances would you select to use an interpreted language?

  Implementation of memory management

Paper describes about memory management. How memory is used in executing programs and its critical support for applications.

  Define open and closed loop control systems

Define open and closed loop cotrol systems.Explain difference between time varying and time invariant control system wth suitable example.

  Prepare a proposal to deploy windows server

Prepare a proposal to deploy Windows Server onto an existing network based on the provided scenario.

  Security policy document project

Analyze security requirements and develop a security policy

  Write a procedure that produces independent stack objects

Write a procedure (make-stack) that produces independent stack objects, using a message-passing style, e.g.

  Define a suitable functional unit

Define a suitable functional unit for a comparative study between two different types of paint.

  Calculate yield to maturity and bond prices

Calculate yield to maturity (YTM) and bond prices

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd