• Home
  • Southern New Hampshire University
  • Network Defense CYB-310-T5690
  • IDS Best Practices and Recommendations for Small Business Network Protection

IDS Best Practices and Recommendations for Small Business Network Protection

I. IDS Best Practices Table Southern New Hampshire University CYB 310 Project Two Stepping Stone Template 1 Southern New Hampshire University IDS Best Practices IDS component Network Sensors Responses Database and storage The IDS Console What does it detect? This component looks at the network packets that are recorded and then compares them to a database of known intrusion activity signatures. It there is a matching result to a signature on file then the sensor will notify the admin. This component can help with guiding you on countermeasures or that may be implemented when there is an attack on the system. It can also tell you how to improve upon your network's security. This component can be used as a library of sorts to help detect any attacks that have happened before or in other situations. This component is where you perform administrative tasks depending on how you have designed you IDS you can use it to configure sensors, agents, and What could a threat actor accomplish if you were not monitoring this component? Tenet of the security (CIA) triad most affected Threat actors can go undetected and wreak more havoc on a system or network since if we do not monitor this component. Availability Threat actors can continue to inflict damage on your systems and network longer if you do not monitor this component of an IDS. However, if you monitor this component, you would have a list of readily available countermeasure at your fingertips. Making sure you monitor that your database for you IDS is up- to-date is important because threat actors can potentially take advantage of an outdated database to avoid detection when they are on the attack. If the administrator is not monitoring the console, they will not know anything that is going on in their network. This can give potential attackers the ability to Availability Integrity Availability and integrity 2 Southern New Hampshire University II. Application Question: A small business start-up in the finance sector with one office location has identified a need for better network protection. It has identified IDS as a great low-cost solution. What IDS components would you recommend the company implement? Justify your response with at least two recommended components. III. A. The three component I would strongly recommend to the small business would be the networks sensors, the IDS console, and the database. The reason I believe that the network sensors, IDS console, and the database are important and necessary is because as a small business it sounds like they do not have the funds or the time to hire people to monitor their system consistently and constantly for attackers. The sensor will automatically sense live attacks happening on their network based on what the database has stored in it. Then a report will be sent listing security concerns to the security professional for the business. The security professional can then look at the reports in the IDS console and implement the necessary countermeasures to the system. 3