What Is Intrusion Detection System? | IDS

 Intrusion detection Systems are specific softwares designed to detect unwanted intrusions. They are a must in any network. Let’s learn why they are necessary, how they work.

Intrusion Detection System (IDS) (IDS) are classified according to the... |  Download Scientific Diagram

Types of Intrusion Detection Systems
1. Host Based- Detecting intrusions that may happen on machine level, i.e. on Hosts.
2. Network based- Detecting intrusions that may happen on Network level.

What does an IDS do?
Its basic function is to reports intrusions, it is not supposed to take any actions. As the actions in this case always require an expert to handle. So, an IDS is like an alarm system, it is a mature technology that has significant utilisation.

Please note an IDS is not a replacement for systems like Firewalls etc. 

Also, It is not a low maintainance tool, it requires qualified experts as handlers. It is expensive and advance technology.

IDS in Action :
Imagine an attacker trying to hack into a company’s network.
Attacker uses Nmap to find open ports,
Generally, all network today have Wireshark as a network sniffer, so it logs all activities and related ip addresses.
Here IDS comes in action and presents recorded data to the victim, so that victim can further take steps.

IDS Alerts:

Intrusion Detection System (IDS) and it's function SIEM/SOC

Alerts are generated only after event of interest(EOI). There are a set of rules that are to be applied to IDS and according to those rules, alerts are generated.

They are generally like :

if : "this event happens,"
Send Alert!

There are generally four events:

1. True positive- IDS has generated an alert, and it is true positive and significant for an attack.
2. True Negative-there is no alert, as well as no attack
3. false positive- alert generated, but no attack, vulnerability exploited but no attack has been reported.
4- false negative- IDS is sleeping while we were hacked.

you should consider which one is worst for your network?
you may not afford having false negative, but you might be okay with some other alert, depends on your assets.

Types of Alerts may be- a popup, beep sound, email, SMS.

IDS used by Human Resource:

Digital HR - HR transformation and talent management

Yes, IDS is also used by HR.

It is basically a content monitoring system, it is like a spy on employees, an ethical one, monitoring all the instant messages, websites visited, emails and pretty much every activity. The resources given to you are only meant for official purposes (Like emailid or devices like laptop)
Also, it helps to know an inside attacker. as it can detect suspicious conversations between employees. Basically people violating company acceptable use policy are reported.

Stay tuned for more such articles,
Thank you for your time!

Post a Comment

Previous Post Next Post