System Intrusion Detection and Prevention
摘要
Psychologically there is value attached to ownership of an asset. How much is spent on protecting the asset determines the value of the asset. Once a resource has been judged to have value, no matter how much protection given to it, there is always a potential that the security provided for the resource will, at some point, fail. This notion has driven the concept of system security and defined the disciplines of computer and computer network security. Computer network security is made up of three principles: preventionPrevention, detection, and response. Although these three are fundamental ingredients of security, most resources have been devoted to detection and preventionPrevention because if we are able to detect all security threatsSecuritythreat and prevent them, then there is no need for a response. IntrusionIntrusion detection detectionDetection, intrusion is a technique of detecting unauthorized accessUnauthorized access to a computer system or a computer network. An intrusion into a system is an attempt by an outsider to illegally gain access to the system. Intrusion preventionPrevention, on the other hand, is the art of preventing unauthorized accessUnauthorized access of a system’s resources. The two processes are related in a sense that while intrusionIntrusion detection detectionDetection, intrusion passively detects system intrusions, intrusion preventionPrevention actively filters network traffic to prevent intrusion attempts. This chapter focuses on these issues.