Skip to main content

Understanding Intrusion Detection Systems (IDS) with Dr. Dorothy Denning

N2K NetworksJanuary 20, 20269 min71 views
26 connections·40 entities in this video→

Defining Intrusion Detection Systems

  • πŸ’‘ An Intrusion Detection System (IDS) is defined as a system that monitors for malicious or unwanted activity.
  • 🎯 It either raises alerts when such activity is detected or blocks the traffic from reaching its target.

Historical Foundations of IDS

  • 🧠 Dr. Dorothy Denning is highlighted as a pioneer in computer science and security, with research in the 1970s and 1980s laying foundations for cryptology, information warfare, and data security.
  • πŸ”‘ Denning invented lattice-based access controls (LBACs) in 1975 and, with Peter Noman in 1984, developed the first intrusion detection expert system (IDES).
  • πŸ“œ Her 1986 paper, "An Intrusion Detection Model," established the groundwork for the first commercial IDS tools.

Types and Evolution of IDS

  • πŸ’» Host-based IDS are placed on a single system and monitor only that computer.
  • 🌐 Network-based IDS inspect traffic across an entire network, historically existing as standalone hardware but now often integrated into modern firewalls as subscription services.
  • πŸ” Modern IDS look for intrusions using known signatures or by detecting anomalies in traffic.

Challenges and Limitations of IDS

  • ⚠️ A significant challenge is false positives, where the system incorrectly flags legitimate activity as malicious, leading to alert fatigue for analysts.
  • πŸ“‰ Another critical issue is false negatives, where the system fails to detect actual malicious traffic in progress.

IDS in Practice and Related Concepts

  • πŸ› οΈ Intrusion detection systems can be configured as passive monitoring devices or inline monitoring systems for more control.
  • πŸ“ˆ Professor Messer's work is referenced for explaining IT and computer security concepts, including IDS and Intrusion Prevention Systems (IPS).
  • πŸš€ Both IDS and IPS are crucial components in security stacks, with IPS actively blocking traffic while IDS primarily alerts.
Knowledge graph40 entities Β· 26 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover Β· drag to explore
40 entities
Chapters4 moments

Key Moments

Transcript33 segments

Full Transcript

Topics15 themes

What’s Discussed

Intrusion Detection SystemIDSIntrusion Prevention SystemIPSCybersecurityNetwork SecurityMalicious ActivityFalse PositivesFalse NegativesDr. Dorothy DenningProfessor MesserHost-based IDSNetwork-based IDSCobalt StrikeSecurity Stack
Smart Objects40 Β· 26 links
PeopleΒ· 4
CompaniesΒ· 3
ConceptsΒ· 24
ProductsΒ· 2
MediasΒ· 4
EventsΒ· 3