|
|
| |
 |
|
Save This Report Details To My Insight
|

 |
|
| The Science of Intrusion Detection System |
|
| Title: |
The Science of Intrusion Detection System
View This Document
|
| Report Type: |
White Papers |
| Report Summary: |
Among the many vendors of intrusion detection systems (IDS), there is marked variation on what constitutes a network intrusion. This has led to many confusing claims by vendors in the IDS market about the best methodologies and solutions. This paper discusses the pros and cons of the various intrusion detection methodologies and explains the Cisco approach for IDS products. The detection methodologies discussed in this paper include simple pattern matching, stateful pattern matching, protocol decode-based signatures, heuristic-based signatures, and anomaly detection. Although addressing each of these analysis methodologies in detail is beyond the scope of this paper, it covers the basic concepts and differences between the approaches.
The term "signature" in this document refers to a set of conditions that, when met, indicate some type of intrusion event. The algorithm used by the signature could be based on any of the five methodologies covered in this paper (for example, an "anomaly detection signature"). It is important to make this distinction because the term signature is generally more closely associated with the pattern match rather than the other methodologies. In fact, this often leads to misconceptions that a signature-based IDS is limited to only pattern matching, so this definition precludes such misconceptions.
|
| Language: |
English |
| File Type: |
PDF |
| No Of Page(s): |
5 |
| Company's Name: |
Cisco Systems
|
|
|
| |
| Research other technical white papers, webcasts, case studies and product literature on the following categories:
Access Control Solutions
Anti Virus
Security Monitoring
Usage Management/Monitoring
Firewalls
Intrusion Detection
Identity Management (security)
Vulnerability Assessment
Service Denial Attacks
Intrusion Prevention
IPSec
Network Security Appliances
Virus Detection
Wireless Security
Vulnerability Assessment
WEP
|
|
|