Traffic Analysis

Firewall

Intrusion Detection System

Audit Record

  • Native Audit Record:使用系统中现有的软件收集用户的活动信息
  • Detection-Specific Audit Record:使用专门的软件收集用户活动信息

Distributed IDS

Pasted image 20230403164744.png

How to profile attack more? - Honeypot

Honeypot 可以引诱潜在攻击者远离关键系统,同时收集攻击者的攻击信息
Pasted image 20230403170241.png

How accurate is IDS?

  • Detection rate / True Positive Rate (TP): 检出攻击的概率
  • False Alarm / False positive Rate (FP): 错报攻击的概率

Intrusion Prevention System