What Are Intrusion Detection Systems?

September 18, 2008
By techgeek

Intrusion Detection System (IDS) are a necessary part of any strategy for enterprise security. What are Intrusion Detection systems? CERIAS, The Center for Education and Research in Information Assurance and Security, defines it this way:brbrldquo;The purpose of an intrusion detection system (or IDS) is to detect unauthorized access or misuse of a computer system. Intrusion detection systems are kind of like burglar alarms for computers. They sound alarms and sometimes even take corrective action when an intruder or abuser is detected. Many different intrusion detection systems have been developed but the detection schemes generally fall into one of two categories, anomaly detection or misuse detection. Anomaly detectors look for behavior that deviates from normal system use. Misuse detectors look for behavior that matches a known attack scenario. A great deal of time and effort has been invested in intrusion detection, and this list provides links to many sites that discuss some of these effortsrdquo;(http://www.cerias.purdue.edu/about/history/coast_resources/intrusion_detection/)brbra href=http://www.readysetwrite.com/security/what-are-intrusion-detection-systems/ target=’_blank’What are Intrusion Detection Systems?/abrThere is a sub-category of intrusion detection systems called network intrusion detection systems (NIDS). These systems monitors packets on the network wire and looks for suspicious activity. Network intrusion detection systems can monitor many computers at a time over a network, while other intrusion detection systems may monitor only one.brbrWho is breaking into your system?brbrOne common misconception of software hackers is that it is usually people outside your network who break into your systems and cause mayhem. The reality, especially for corporate workers, is that insiders can and usually do cause the majority of security breaches. Insiders often impersonate people with more privileges then themselves to gain access to sensitive information.brbrHow do intruders break into your system?brbrThe simplest and easiest way to break in is to let someone have physical access to a system. Despite the best of efforts, it is often impossible to stop someone once they have physical access to a machine. Also, if someone has an account on a system already, at a low permission level, another way to break in is to use tricks of the trade to be granted higher-level privileges through holes in your system. Finally, there are many ways to gain access to systems even if one is working remotely. Remote intrusion techniques have become harder and more complex to fight.brbrHow does one stop intrusions?brbrThere are several Freeware/shareware Intrusion Detection Systems as well as commercial intrusion detection systems. More on a href=http://www.readysetwrite.com/ target=’_blank’Intrusion Detection Systems/a.

Comments are closed.

Share |
Find The Lowest Rates Among Internet, Cable TV & VoIP Providers at Telecom Pricer

Sites of Interest

> Air Hockey Tables

> Direct TV



> Where can I buy the best chess sets from in the UK? ChessBaron, of course.

More Resources