City University of Hong Kong · FACULTY OF INFORMATION TECHNOLOGY

IS6523 Chap.6 Intrusion Detection, Scanning and Biometric Controls

- one subject, every graph, every model, every mark
9 Chapters5-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 6 of 10 · IS6523

Intrusion Detection, Scanning and Biometric Controls

An alarm that reacts, and three things it can do

Detection and prevention systems are introduced by analogy with burglar alarms, joining older detection methods to the ability to react that prevention technology adds; because most products now do both, one term covers the category.

Three reactions are named: terminating the network connection or the attacker's session, reconfiguring the firewalls, routers and switches so that the target cannot be reached, and altering the content of the attack itself, for example by stripping an infected attachment before the message is delivered.

Two independent choices that students routinely merge

Every question about a detection system resolves into placement and comparison basis, and they are independent.

Placement is network or host: a network sensor covers a large segment passively and is often undetectable, but can be swamped by volume and cannot read encrypted packets, while a host sensor sees local events and traffic already decrypted at the machine, at the cost of management burden, its own exposure to attack and a performance overhead.

Comparison basis is signature or anomaly: signatures match predetermined patterns and must be continually updated, and an attacker who is slow and methodical may not match one, while a baseline approach can detect new kinds of attack but needs processing capacity and generates false positives.

Research tools, legal limits and the arithmetic of authentication

The scanning half names footprinting, the organised research of a target's internet addresses, and fingerprinting, their systematic examination, and sets out port ranges, vulnerability scanners, packet sniffers with four conditions on their lawful use, and decoy systems whose trace function can violate privacy.

The authentication half restates the four access processes, gives three mechanisms and a password practice, and then supplies the only comparison figure in the topic: a false reject rate, a false accept rate, and the crossover point at which the two are equal.

In this chapter

What this chapter covers

  • 01

    Three things a prevention system can do to an attack in progress

  • 02

    Network against host placement, and the evidence each can reach

  • 03

    Signature against anomaly, and the clipping level

  • 04

    Selecting a product through three sets of questions

  • 05

    Footprinting, fingerprinting and the port ranges

  • 06

    The four lawful conditions on a packet sniffer

  • 07

    Decoys, tracing and the privacy limit

  • 08

    Three authentication mechanisms and multiple factors

  • 09

    Type I error, Type II error and the crossover rate

Worked example · free

Defend the sensor that raises the fewest alerts

Q [6 marks]. AskSia-authored practice. A bank's network sensor raises eleven hundred alerts in a month, nine of which are escalated. Its four host sensors raise forty, of which eleven are escalated. A manager proposes retiring the host sensors because they produce so little. Reply. The marks shown are an AskSia study allocation, not a University marking scheme.
  • 2Compare the escalation rates and say which is expected.
  • 3Name what the host sensors see that the network sensor cannot.
  • 1State the correct response to the volume problem.
The network sensor escalates under one per cent, which is the outcome the course predicts for that placement, since a network sensor infers what normal traffic looks like and therefore yields far more false positives. The host sensors escalate more than a quarter of what they raise, and they reach two classes of evidence the network sensor structurally cannot: local events on the server itself, and traffic that arrived encrypted and has been decrypted at the host. Retiring them would remove the only detection covering encrypted sessions to the payment servers. The correct response is to keep both and tune the noisy one, because an alarm nobody answers is the failure mode the session names explicitly.
Sia tip — Decide placement and comparison basis separately, and say both out loud. Network or host is one question; signature or anomaly is another. A missed slow insider is a basis failure, and answering it with an argument about placement scores nothing.
Glossary

Key terms

Footprinting
Organised research into which internet addresses a target organisation owns or controls, carried out before any exploitation.
Fingerprinting
The systematic examination of an organisation's network addresses, producing a detailed analysis of the intended targets.
Anomaly Based Detection
Detection that establishes a baseline from normal traffic and samples activity against it, notifying an administrator when activity falls outside the baseline parameters.
False Reject Rate
The Type I error of a biometric system, in which a legitimate user is turned away. It rises as the threshold is tightened.
False Accept Rate
The Type II error of a biometric system, in which an impostor is admitted. It falls as the threshold is tightened.
Consolidated Enterprise Management
A service collecting data from many host and network sensors so that patterns can be sought across systems and subnetworks.
Network Access Control
A control governing how devices and users reach resources on a network, which the course requires to be scalable, vendor neutral and able to support wired, wireless, physical, virtual and cloud deployment.
FAQ

Intrusion Detection, Scanning and Biometric Controls FAQ

Why does a network sensor produce so many more false alarms than a host sensor?

Because it is inferring rather than observing. The course states that network placed systems yield many more false positive readings, since they read the network activity pattern to work out what is normal and what is not, and must match both known and unknown attack strategies against a knowledge base. A host sensor watches one machine's files and behaviour, which is a far smaller and better defined space to be wrong about.

An intrusion ran slowly for weeks using valid credentials and was missed. Which choice explains it?

The comparison basis, not the placement. A signature system matches predetermined attack patterns, and the course notes specifically that a slow and methodical attacker may slip through because signatures include factors based on the duration of events. Nothing about activity using legitimate credentials resembles a known pattern.

A baseline approach is the one with a chance, at the cost of processing capacity and more false positives.

What makes a published false accept rate useless on its own?

That any false accept rate can be reached by tightening the threshold until legitimate users are turned away. The two error types move in opposite directions, so a figure quoted without the threshold it was measured at says nothing. The crossover error rate, the point at which the two are equal, is the figure the course gives for comparing systems, and it is what to ask a vendor for.

Is it acceptable to run attacker tools against your own network?

The course says yes and treats it as part of the job. No objection is raised to security administrators picking up an attacker's tools to examine their own defences, and the security manager should be able to see the organisation's systems from a potential attacker's viewpoint. Two tools carry limits, though.

A packet sniffer requires network ownership, owner authorisation, user knowledge and consent, and a justifiable business reason, and the tracing of an intruder can violate privacy.

Study strategy

Exam move

Draw a two by two with placement on one axis and comparison basis on the other and put a realistic example in each cell, because the commonest error here is answering a placement question with a basis argument. Then sketch the two error curves and mark the crossover, and say aloud what tightening the threshold does to each.

Finish by reciting the four conditions on lawful sniffing, which is a cheap mark and a question the ethics session can also ask.

Working through Intrusion Detection, Scanning and Biometric Controls in IS6523? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Intrusion Detection, Scanning and Biometric Controls question and get a clear, step-by-step explanation grounded in how IS6523 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 6 of your City University of Hong Kong subjects - and 1,000+ Bibles across every Australian university.
Sia - your IS6523 tutor, unlimited, worked the way the exam marks it
The full 5-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works