• Home
  • Southern New Hampshire University
  • Network Defense CYB-310-T5690
  • Network Defense CYB-310-T5690

Network Defense CYB-310-T5690

Southern New Hampshire University Walter Lawrence CYB 310 Project Two Stepping Stone I. IDS Best Pracces Table Southern New Hampshire University IDS Best Prac ces IDS component What does it detect? What could a threat actor Tenet of the security (CIA) accomplish if you were not triad most affected monitoring this component? Network Sensor Analyze network traffic or A threat actor could in fact Availability -- I chose this network activity and generate take over the network acting as because without the security events. an admin or IT person forcing availability of this monitoring the system to allow them in device it would make it easy and put the network in for all sorts of data to be jeopardy. stolen. A threat actor could potentially Integrity -- I chose is because Console Monitors events and to alert and control the sensors gain access to the network and with this it keeps the network make changes in order for the in tact of all important data and system to think its still safe but makes it harder for data to be in reality, they are already stolen. taking data. A threat actor could potentially Integrity -- I chose this because Detection Engine Events generated by sensors are recorded by an engine. make a policy change that the if anything is changed or These are recorded in a 2system thinks is safe or make forced to changes it could Southern New Hampshire University II. Applica on Ques on A. The recommendation I would make to this company is first using a NIDS (network-based Intrusion Detection System). The reason is that the NIDS monitors the network that is not controlled by a certain policy or firewall rules. It can analyze packets individually as they enter the network to either block if malicious or allow them through if they are safe. The second recommendation I would say to use is monitoring agent software. This type of software when implemented can see what types of changes are made like if someone's access changes it would alert the IT team and stop this person from accessing the network if they are not allowed. Doing this not only helps keep the data confidential but also helps stop vulnerable areas from being hacked and then the IT team can look into making that network area stronger and less susceptible to attacks Sources Nagori, B. A. I. (n.d.). How Does the Intrusion Detection System (IDS) work? Retrieved September 21, 2022, from https://linuxhint.com/intrusion-detection-system-ids-work