Notes on Security
- The main role of IDS is to report attacks on the monitored system/network.
- The NIDS is not a replacement to the firewall according to the defense in depth (DiD) concept
The ability of something or someone to influence the behavior of a group of people is social engineering.
A basic honeypot can be made by monitoring the non-service ports on an active server
Port scanning is a passive phase of attacking
Encrypting traffic makes it harder. for NIDS to analyze
The more restrictive Firewall must have the default deny rule
The worms. use the network to send copies of themselves to other machines
The defense in depth DiD concept deals with the information layer followed by The application, the host, and the network layers