Testbusters.net
  Testbusters.net
  Guaranteed Pass!
Questions, email us!
    Test Questions
Home  
Guarantee  
About Us  
FAQ  
Purchase
 Products     Microsoft®    CompTIA®    Cisco®    Subnetting Made Easy
Access Control Techniques
  Mandatory
  Discretionary
Access Control Models
  Lapadula
  Clark-Wilson
  Biba
Intrusions
  DoS Attack
  IDS
WAN Security
  Firewall
  VPN
  Authorization
  Viruses
  Public Keys
  Private Keys
 SY0-101
  Test 1
 N10-003
  Test 44
  Test 12
 Aplus
  Test 11
  Test 1
 W2K
  Test 1
 More Test
Questions
Intrusion Detection
Primarily an intrusion detection system is designed as it’s name implies, detect network intrusions. They are utilized to watch for confidentiality, integrity, and availability violations. Automation of real time system events, inspection and audit logs are of primary concern to the administrator.
Some intrusions systems also have the ability to rate the overall network performance.
The two primary types of IDSs are; The host-based IDS concerns itself with suspicious activity on a single host, where as the network-based IDS watches over the entire network medium.
The host-based IDS has the ability to identify anomalies that the network-based cannot see on that individual system.
The network-based IDS evaluates network packets as they traverse the network, and is typically installed on a single system within the network. Doing this, enables hardening the system, allows the system to operate transparently on the network, and reduces the number of overall vulnerabilities to the system.
Another significant advantage of the network-based IDS is that it has no impact on network performance where as the host-based IDS may consume considerable system resources.

The two methods in which an IDS can detect a malicious event are;


Copyright ©2002-2006 Testbusters.net. All Rights Reserved.
Testbusters.net is not sponsored, endorsed or affiliated by any associated vendor.
Associated venders include, but are not limited to, Microsoft®, Cisco®, CompTIA®, Novell® etc.