Southern New Hampshire University
Walter Lawrence CYB 310 Project Two Stepping Stone
I. IDS Best Pracces Table
Southern New Hampshire University IDS Best Prac ces
IDS component
What does it detect?
What could a threat actor
Tenet of the security (CIA)
accomplish if you were not
triad most affected
monitoring this component?
Network Sensor
Analyze network traffic or
A threat actor could in fact
Availability -- I chose this
network activity and generate
take over the network acting as because without the
security events.
an admin or IT person forcing
availability of this monitoring
the system to allow them in
device it would make it easy
and put the network in
for all sorts of data to be
jeopardy. stolen. A threat actor could potentially Integrity -- I chose is because
Console
Monitors events and to alert
and control the sensors
gain access to the network and
with this it keeps the network
make changes in order for the
in tact of all important data and
system to think its still safe but makes it harder for data to be
in reality, they are already
stolen.
taking data. A threat actor could potentially Integrity -- I chose this because
Detection Engine
Events generated by sensors
are recorded by an engine.
make a policy change that the
if anything is changed or
These are recorded in a
2system thinks is safe or make
forced to changes it could
Southern New Hampshire University
II. Applica on Ques on A. The recommendation I would make to this company is first using a NIDS (network-based Intrusion Detection
System). The reason is that the NIDS monitors the network that is not controlled by a certain policy or firewall
rules. It can analyze packets individually as they enter the network to either block if malicious or allow them
through if they are safe. The second recommendation I would say to use is monitoring agent software. This type of
software when implemented can see what types of changes are made like if someone's access changes it would alert
the IT team and stop this person from accessing the network if they are not allowed. Doing this not only helps keep
the data confidential but also helps stop vulnerable areas from being hacked and then the IT team can look into
making that network area stronger and less susceptible to attacks
Sources
Nagori, B. A. I. (n.d.). How Does the Intrusion Detection System (IDS) work? Retrieved September 21, 2022, from
https://linuxhint.com/intrusion-detection-system-ids-work