Project Two - Bolinsky 1 Cyb-310-J8939 Network Defense-24EW4 Project Two - IDS Analysis Michael Bolinsky Southern New Hampshire University Professor Ostering May 16, 2024
Network Analysis - Bolinsky 2 Analysis I. IDS and Security Objectives-Critical Thinking Questions A. What component of an IDS is best prepared to help with the loss of confidentiality? Multiple components are required for an IDS System to be successful in protecting the confidentiality of a network. The component best equipped to prevent a loss of confidentiality would be sensors and proper response. Sensors monitor network traffic, system logs, and other data sources for suspicious activity. They are the first component of an IDS. These sensors can either be host- or network-based. They provide alerts when potential breaches are detected. Once a breach has been detected a proper response is required and this is in the response components of an IDS. The response mechanism for dealing with discovered threats to mitigate the effects of the intrusion can include restricting traffic, quarantining affected systems, or triggering automated actions. Through these components the confidentiality aspect of the CIA Triad is protected. B. What are the indicators of malware that an IDS could detect that may result in the loss of integrity? The indicating factors of malware detected by an IDS can include unusual network traffic patterns, unexpected system behaviors, unauthorized access attempts, and malicious payloads to name a few. An IDS through the analysis of network traffic can detect these anomalies and provide notification of possible attacks and allow human operators to provide the necessary steps required to insure the data of a company is fully protected.
Network Analysis - Bolinsky 3 C. How can an IDS be used to detect the loss of availability? The loss of network availability detected by an IDS is through it's sensors as the detection aspect. Sensors would compare suspicious activity to the signature database of known threat types. Once an anomaly is noted the IDS's analysis engine examines them to determine whether they reflect actual threats by various techniques like signature-based detection, anomaly detection, and behavioral analysis. Once evaluated an IDS would either issue an alert warning or resume normal traffic. In both such instances an IDS would document the activity to be reviewed by analysis. II. Configuring an IDS-Scenario Based Questions A. Create a brief fictitious scenario of a company that resides within two buildings. Include a short profile of its data assets, industry, and size. Veteran Aid Corp (VAC) has an administration building and a medical clinic. Its mission is veteran assistance filling a gap missed through federal offices by providing medical services and employment aid to veterans and their families. The data assets controlled through VAC are veteran medical information, service records, and personal information. B. Identify two components that you would implement to provide the best IDS protection for your fictitious company. Justify your response. I would implement a hybrid based IDS system that would provide the best detection and response capabilities. Since this company is a