What is a simple and effective way to correlate events? different TCP destination ports different TCP source ports same alert timestamp same alert severity level same IP 5-tuple 1 point 8. Question 8
Added by Adam B.
Step 1
Correlation involves identifying relationships or patterns between different events to gain insights or detect anomalies. Show more…
Show all steps
Your feedback will help us improve your experience
Akash M and 97 other AP CS educators are ready to help you.
Ask a new question
Labs
Want to see this concept in action?
Explore this concept interactively to see how it behaves as you change inputs.
Key Concepts
Recommended Videos
Create a matrix of five common, well-known UDP ports and five common, well-known TCP ports. For each port: [Port #], state the applicable port number (1 port # per row); [Use of Port] in plain English, give a functional description of how the port is used; [Port Service], name the service that runs on that port (usually a short name), [Secure] identify whether it is a secure communication port with a simple Yes or No, [Lab] finally indicate any labs you completed in Week 1 or 2 of this course in which you saw that port (if this port wasn't seen, enter None).
Akash M.
1. Discuss the four different types of suspicious traffic signatures: 1. Informational 2. Reconnaissance 3. Unauthorized access 4. Denial of service . 2. Provide a detailed description of how each of the following TCP flags are utilized: 1. SYN (Synchronize) 2. ACK (Acknowledgement) 3. PSH (Push) 4. URG (Urgent) 5. RST (Reset) 6. FIN (Finished)
Madhur L.
Texts: Basic attack analysis: 1. Look at captures no. 20 and 22. (You can use the "Go" link at the top of the Wireshark screen to quickly go to a specific capture.) Both packets are ICMP traffic, but there are subtle differences between them. Compare the time-to-live and data field sizes in the two packets. What differences do you see? 2. Do a little Internet research to discover which operating systems use the specific values in their ping commands. What operating system generated the echo request in capture 20? 3. Review packet no. 37 and beyond. What do you think is taking place here? 4. Look at capture 22846. What is suspicious about the flag settings in this packet? 5. What is the IP address of the host being targeted?
Recommended Textbooks
Computer Science and Information Technology
Introduction to Programming Using Python
Computer Science - An Overview
Transcript
18,000,000+
Students on Numerade
Trusted by students at 8,000+ universities
Watch the video solution with this free unlock.
EMAIL
PASSWORD