What sort of attack is it intended to detect

Assignment Help Computer Network Security
Reference no: EM131492020

Assignment: Intrusion Detection and Intrusion Prevention

Part 1: True or False Questions.

1. T F To have a Snort rule match on both inbound and outbound traffic, the rule should use the flow:to_server,from_client,established; option.

2. T F Host-based IDS can be used to monitor compliance with corporate policies such as acceptable use of computer resources.

3. T F An on-demand operational IDS model is not suitable if legally admissible data collection is required.

4. T F Current criminal and civil procedure laws and rules of evidence do not provide clear guidance on digital and electronic forms of evidence such as IDS logs.

5. T F Snort unified output plug-ins can be used to off-load computing tasks from the core Snort program to improve overall performance.

6. T F Thresholds used in Snort alert rules can cause false negatives if the attacker works slowly enough.

7. T F Network-based IDS provides no protection against internal threats.

8. T F When a "pass" rule is matched in Snort, no other rules are evaluated.

9. T F To ensure proper execution of Snort rules using the "uricontent" option the HTTP Inspect preprocessor must be installed and configured in Snort.

10. T F There are no monitoring situations that justify real-time intrusion response.

Part 2: Short Answer Questions.

1. False positive and False negative

a. Define and differentiate false positive and false negative.
b. Which is worse, and why?
c. Give one example of each, drawn from any context that demonstrates your understanding of the terms.

2. Snort rule

a. Describe the components of the following Snort rule.

alert ip any any -> any any (msg:"BAD-TRAFFIC same SRC/DST"; sameip; reference:bugtraq,2666; reference:cve,1999-0016; reference:url,www.cert.org/advisories/CA-1997-28.html; classtype:bad-unknown; sid:527; rev:8;)

a. What sort of attack is it intended to detect?
b. What network traffic pattern information is it looking for?

3. User-centric and target-centric monitoring:

a. What are the key differences between user-centric and target-centric monitoring in behavioral data forensics?
b. Is one perspective preferred over the other?
c. If so, what are some of the advantages of the preferred choice, or disadvantages of the non-preferred choice?

4. Write a rule using Snort syntax to detect an internal user executing a Windows "tracert" command to identify the network path to an external destination. What changes, if any, would you need to make to this rule to make it also work for a Unix/Linux "traceroute"?

5. As Trost noted, most network IDS tools are designed to optimize performance analyzing traffic using a variety of protocols specific to TCP/IP wired networks.

a. Describe at least two intrusion detection scenarios where specialized types of monitoring and analysis are called for

b. what limitations exist in conventional NIDS that make them insufficient to provide effective intrusion detection in the environments corresponding to these scenarios.

6. Multi-event signature

a. What is a multi-event signature?
b. Provide at least two examples of multi-event signature activities or patterns that might be monitored with an intrusion detection system.

7. Anomaly-based intrusion detection

a. What are the operational requirements necessary to perform anomaly-based intrusion detection?

b. How does the information gathered about network traffic by anomaly-based IDS tools differ from the information gathered by signature-based NIDS?

8. Many people perceive intrusion detection to be a constant, all-the-time security function.

a. Identify and describe at least two "part-time" intrusion detection operational models,
b. and for each give an example of a usage scenario that would call for part-time monitoring.

9. Are organizations legally obligated to use intrusion detection capabilities? Why or why not?

10. Imagine you are tasked with monitoring network communication in an organization that uses encrypted transmission channels.

a. What are the limitations of using intrusion detection systems in this environment?
b. What methods would you employ to accomplish this task?

Part 3: Essay Questions. Maximum length: 2 pages each, excluding references.

1. In 2003, a well-publicized report from IT analyst firm Gartner predicted that the market for stand-alone IDS tools would soon disappear, and urged Gartner clients to cease investing in IDS tools in favor of firewalls. Last week, U.S. cyber security czar Howard Schmidt publicly called for enterprise network intrusion detection, and asked, "Why haven't we done this already?" Clearly, the obsolescence of IDS tools by 2005 did not occur as Gartner predicted.

a. What factors have been most important in the continued viability of the IDS market?

b. Based on what you have learned about IDS and IPS tools, do you think these tools will continue to be used as a key security component? Why or why not?

2. In early 2008, the U.S. Department of Homeland Security stated publicly that it wanted more intrusion detection capabilities, in particular citing a need to move to mandatory real-time intrusion detection for federal government networks, as an expansion of current passive, voluntary monitoring. The current manifestation of this goal is the Einstein program, which while officially in a pilot phase is likely to be expanded significantly soring in 2011.

Article: DHS releases new details on Einstein 3 intrusion prevention pilot By Ben Bain.

a. Using what we have learned in this course and your own knowledge of IDS operational models, requirements, and other characteristics associated with selecting and using the most appropriate types of intrusion detection and prevention, what is your response to the proposal to implement comprehensive intrusion detection and prevention for all network traffic to or from U.S. government agencies?

b. What are some of the key obstacles faced in rolling out an intrusion detection capability of this sort?

c. Identify and describe at least three challenges that DHS should consider when planning the Einstein deployment.

Reference no: EM131492020

Questions Cloud

What is current share price : Metallica Bearings, Inc., is a young start-up company. No dividends will be paid on the stock over the next ten years, what is the current share price?
List basic elements of a fiber optic communication system : List five advantages of an optical communications link. Define refractive index.
What was the average real risk premium : What was the average real risk-free rate over this time period? What was the average real risk premium?
What are the four factors that contribute to attenuation : What are the typical core/cladding sizes (in microns) for multimode fiber?
What sort of attack is it intended to detect : What sort of attack is it intended to detect? What are the key differences between user-centric and target-centric monitoring in behavioral data forensics?
What must the coupon rate be on the bonds : The bonds make semiannual payments. What must the coupon rate be on the bonds?
What is meant by the zero-dispersion wavelength : Define dispersion. What are three types of dispersion?
Compute the net proceeds to the presley corporation : Compute the earnings per share immediately after the stock issue. Compute the net proceeds to the Presley Corporation.
What is the statement of cash flows : What is the statement of cash flows and briefly describe 3 types of business activities it classifies? Discuss two methods of presenting operating activities

Reviews

Write a Review

Computer Network Security Questions & Answers

  How much information is available to potential hackers

Maintaining a proactive approach on security requires that an organization perform its own hacking footprinting to see how much information is available to potential hackers

  Is there any way that eve can read encrypted communications

Suppose that Eve runs a key server. Alice downloads a key from the key server which Eve claims is Bob's public key. Bob downloads a key from the key server which Eve claims is Alice's public key.

  Examine the contents of the security and privacy tabs

Using a Microsoft Windows XP, Vista, or 7, open Internet Explorer. Click Internet Options on the Tools menu. Examine the contents of the Security and Privacy tabs. How can these tabs be configured to provide: (a) content filtering and (b) protecti..

  Describe two potential computer ethics issues associated

Describe two potential computer ethics issues associated with holding computers hostage. Propose two methods that computer users could use to prevent this type of attack.

  Provide secure remote access solution that utilizes network

Provide secure remote access solution that utilizes Network Access Policy controls. Provide easy and manageable workstation image and software deployments. All workstations should be Window 8.

  Analyze the existing security situation in the organization

Analyze the existing security situation in the organization. Identify the predominant electronic and physical threats to communications networks. Explain the importance of explicit enterprise security policies and procedures.

  Design a book publisher database from scratch

You will need to design a Book Publisher Database from scratch, create the database,create the relationships between the three tables, enter the given data into the appropriate tables and then query the database in order to provide required inform..

  Analysis of a small publishing company

A small magazine publisher wishes to determine the best combination of 2-possible magazines to print for the month of July. Backyard magazine, which he has published for years, is a contant seller.

  Application to input a character string

Output the string rotated to the right by a user-defined number of characters (0 or more). For example, Hello world!rotated by two characters would be: Hello world.

  What is data mining and why is it considered controversial

What exactly is "cyber ethics" How is it different from and similar to computer ethics information ethics and Internet ethics and Identify and describe some key aspects of each of the four phases in the evolution of cyber ethics as a field of app..

  Bring voice over internet protocol to the entire

paper in apa format with labels for each section to include an introduction main topicbody and sub-topics and

  Describe specific goals for the process area

Briefly describe what the process area is and why it is needed. Enumerate improvements you expect to see for these process areas in your enterprise.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd