Week 8

In this session we learned about network intrusion detection and analysis.

NIDS: Network-Based Intrusion Detection System used to detect if there are anomalies or suspicious behavior in our personal network.

HIDS: Host-Based Intrusion Detection System

NIPS: Network-Based Intrusion Prevention System used to prevent any attack that is recognized by the system (e.g. ransomware).

Types of IDS:

  1. Commercial:
    • Check point IPS Software Blade
    • Next-Generation Intrusion Prevention System (NGIPS)
    • Extreme NIPS
    • Tipping Point IPS
  2. Open-Source
    • NIDS:
      • Snort
      • Bro
      • Suricata
      • Sagan
    • HIDS:
      • OSSEC
      • Fail2Ban
      • AIDE
      • Samhain

Leave a Reply

Your email address will not be published. Required fields are marked *