• Home
  • Southern New Hampshire University
  • Network Defense CYB-310-T5690
  • Network Defense and IDS

Network Defense and IDS

Walter Lawrence CYB 310 -- Network Defense Southern New Hampshire University Professor Ostering October 6, 2022 IDS Analysis Paper Confidentiality refers to the keeping of data safe and confidential and secured against any outside resources, attackers or wandering eyes that are not supposed to see this data. There are many ways that threat actors can gain access to the system and steal any kind of data they want which can violate the CIA Triade. So, this brings me to the point of using an IDS system. When using an IDS, it monitors the network traffic for any kind of malicious or dangerous traffic that could put the network in harms way and risk the loss of data. IDS can use network or packet sniffing to help determine if traffic is dangerous or not or if there is an open port somewhere that can easily be hacked. IDS primarily is used for anomaly detection and reporting as well as can block the traffic that seems suspicious which can help keep the network safe and the data still intact with its confidentiality (Lutkevich, 2021). As far as integrity goes of the CIA Triade is how the data can be affected. If a network is compromised, then it means the data can be in jeopardy which puts the network in an integrity breach. With this happening all data could be lost which is bad for a company that has a lot of secure or confidential documents. With an IDS either being network based or host based it allows the system to be monitored for any sort of attacks. This device can monitor the network devices, firewalls, and computers for any sort of activity that could warrant an issue. It also will send notifications to the IT team notifying them of a breach and can lock down that port or sector to help with keeping the data safe. It also can gather information on how the attack started so that way it can be rectified for the next time an attack like this happens. IDS also allows customization so if a company needs to update the IDS, they can make those changes to keep the integrity of the network intact. If a company did not have a system like these attackers could easily use this company as target practice which then deteriorates the integrity of this company putting little to no trust in them and whatever they do could potentially cause a loss on clients. With availability this focuses on providing users access to certain parts of the network. So, if an IT person needs full access they will since they work on the network. If a user that is in the finance department wants to access the HR department this could cause needs for approvals as that person might not be allowed to view that confidential data. Most cyber attacks come from hackers disguising themselves as a trusted user or planting viruses that can mirror the user's credentials unlocking them to vie any