IDS
Intrusion Detection Systems
Define an intrusion
Set of actions aimed to compromise security
Activity is suspicious (IDS) if
IDS Components
Audit Data Preprocessor
Detection Engine (+Models)
Decision Engine (+Table)
IDS Functions
IDS Types
IDS responses
Alarm
Cut user access
Reject traffic
…
IDS Problems
IDS before or after firewall
Before can be very slow but after might be quicker.
Before might be required to protect firewall