IS6523 Chap.6 Intrusion Detection, Scanning and Biometric Controls
Intrusion Detection, Scanning and Biometric Controls
An alarm that reacts, and three things it can do
Detection and prevention systems are introduced by analogy with burglar alarms, joining older detection methods to the ability to react that prevention technology adds; because most products now do both, one term covers the category.
Three reactions are named: terminating the network connection or the attacker's session, reconfiguring the firewalls, routers and switches so that the target cannot be reached, and altering the content of the attack itself, for example by stripping an infected attachment before the message is delivered.
Two independent choices that students routinely merge
Every question about a detection system resolves into placement and comparison basis, and they are independent.
Placement is network or host: a network sensor covers a large segment passively and is often undetectable, but can be swamped by volume and cannot read encrypted packets, while a host sensor sees local events and traffic already decrypted at the machine, at the cost of management burden, its own exposure to attack and a performance overhead.
Comparison basis is signature or anomaly: signatures match predetermined patterns and must be continually updated, and an attacker who is slow and methodical may not match one, while a baseline approach can detect new kinds of attack but needs processing capacity and generates false positives.
Research tools, legal limits and the arithmetic of authentication
The scanning half names footprinting, the organised research of a target's internet addresses, and fingerprinting, their systematic examination, and sets out port ranges, vulnerability scanners, packet sniffers with four conditions on their lawful use, and decoy systems whose trace function can violate privacy.
The authentication half restates the four access processes, gives three mechanisms and a password practice, and then supplies the only comparison figure in the topic: a false reject rate, a false accept rate, and the crossover point at which the two are equal.
What this chapter covers
- 01
Three things a prevention system can do to an attack in progress
- 02
Network against host placement, and the evidence each can reach
- 03
Signature against anomaly, and the clipping level
- 04
Selecting a product through three sets of questions
- 05
Footprinting, fingerprinting and the port ranges
- 06
The four lawful conditions on a packet sniffer
- 07
Decoys, tracing and the privacy limit
- 08
Three authentication mechanisms and multiple factors
- 09
Type I error, Type II error and the crossover rate
Defend the sensor that raises the fewest alerts
- 2Compare the escalation rates and say which is expected.
- 3Name what the host sensors see that the network sensor cannot.
- 1State the correct response to the volume problem.
Key terms
- Footprinting
- Organised research into which internet addresses a target organisation owns or controls, carried out before any exploitation.
- Fingerprinting
- The systematic examination of an organisation's network addresses, producing a detailed analysis of the intended targets.
- Anomaly Based Detection
- Detection that establishes a baseline from normal traffic and samples activity against it, notifying an administrator when activity falls outside the baseline parameters.
- False Reject Rate
- The Type I error of a biometric system, in which a legitimate user is turned away. It rises as the threshold is tightened.
- False Accept Rate
- The Type II error of a biometric system, in which an impostor is admitted. It falls as the threshold is tightened.
- Consolidated Enterprise Management
- A service collecting data from many host and network sensors so that patterns can be sought across systems and subnetworks.
- Network Access Control
- A control governing how devices and users reach resources on a network, which the course requires to be scalable, vendor neutral and able to support wired, wireless, physical, virtual and cloud deployment.
Intrusion Detection, Scanning and Biometric Controls FAQ
Why does a network sensor produce so many more false alarms than a host sensor?
Because it is inferring rather than observing. The course states that network placed systems yield many more false positive readings, since they read the network activity pattern to work out what is normal and what is not, and must match both known and unknown attack strategies against a knowledge base. A host sensor watches one machine's files and behaviour, which is a far smaller and better defined space to be wrong about.
An intrusion ran slowly for weeks using valid credentials and was missed. Which choice explains it?
The comparison basis, not the placement. A signature system matches predetermined attack patterns, and the course notes specifically that a slow and methodical attacker may slip through because signatures include factors based on the duration of events. Nothing about activity using legitimate credentials resembles a known pattern.
A baseline approach is the one with a chance, at the cost of processing capacity and more false positives.
What makes a published false accept rate useless on its own?
That any false accept rate can be reached by tightening the threshold until legitimate users are turned away. The two error types move in opposite directions, so a figure quoted without the threshold it was measured at says nothing. The crossover error rate, the point at which the two are equal, is the figure the course gives for comparing systems, and it is what to ask a vendor for.
Is it acceptable to run attacker tools against your own network?
The course says yes and treats it as part of the job. No objection is raised to security administrators picking up an attacker's tools to examine their own defences, and the security manager should be able to see the organisation's systems from a potential attacker's viewpoint. Two tools carry limits, though.
A packet sniffer requires network ownership, owner authorisation, user knowledge and consent, and a justifiable business reason, and the tracing of an intruder can violate privacy.
Exam move
Draw a two by two with placement on one axis and comparison basis on the other and put a realistic example in each cell, because the commonest error here is answering a placement question with a basis argument. Then sketch the two error curves and mark the crossover, and say aloud what tightening the threshold does to each.
Finish by reciting the four conditions on lawful sniffing, which is a cheap mark and a question the ethics session can also ask.
Working through Intrusion Detection, Scanning and Biometric Controls in IS6523? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Intrusion Detection, Scanning and Biometric Controls question and get a clear, step-by-step explanation grounded in how IS6523 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.