Introduction
The interconnectivity of computers for both small and large business organizations is at the core of the success of business especially as electronic commerce dominates the economic landscape and also acts as the main driver in the growth of internet. This interconnection brings together partners, suppliers, customers, and even competitors. To share this information freely and without worry, businesses have to develop a degree of trust. Trust in computer systems is based on security controls and this trust is usually improved by the verification that the security measures work. The disciplines of computer security address three fundamental needs: Prevention , Detection and Response (Proctor, 2001).
However, the last three decades have seen the allocation of a disproportionate number of resources to prevention while leaving out detection and response almost entirely. This has been a grave mistake since these preventive methods have fallen short of protecting corporate assets. In June 1999, it was reported in the New York Times that losses to computer misuse amounted to about $7 billion (Proctor, 2001).
Security Vs Business
It is obvious that business depends on computers for success. For this, a certain amount of access to the computers must be available to vendors, customers, partners, and employees for business to be carried out effectively. As a result, this access results in connections to the wide world web or the use of technology that often exposes networks to outside threats. unfortunately, most preventive security control measures infringes on the free flow of information and managing access controls always results in to slowing down business. Another problem with these perimeter defences are that most of the losses are as a result of untrustworthy insiders. . The 1999 Computer Security Institute/Federal Bureau of Investigation (CSI/FBI) Computer Crime and Security Survey indicates that up to more than 82% of losses in businesses were as a result of insider threats (Proctor, 2001).
Intrusion Detection
Video cameras are not used as prevention devices but provide an effective excellent deterrent and, in case of loss, they can be used to assist in the investigation. In the computer world, this parallel capability is usually known as intrusion detection. Intrusion detection tools are not used for prevention purposes, but they effective deterrents and also provide threat identification capabilities. Intrusion detection is the art of detecting computer misuse and responding to the same. One of the most confusing aspect in intrusion detection is defining it. The IDSG released its final report in December 1997 and provided the following definitions (Proctor, 2001).
Intrusion— Unauthorized access to, and/or activity in, an information system.
Intrusion detection—The process of identifying that an intrusion has been attempted, is occurring, or has occurred.
Misuse—Attacks originating inside the organization.
Most organizations already use an intrusion detection system, mostly it is a simple application that does manua analysis of firewall logs. There are two main types of network detection systems: host and network intrusion detection technologies. Host based intrusion detection systems examine events e.g. what applications were executed and what files were accessed. Network-based systems examine events such the information exchanged between computers. Additionally, there are two types network-based intrusion detection technologies. These are: Promiscuous-mode network intrusion detection and Network-node intrusion detection systems. The best intrusion detection systems are however known as ‘hybrids’ (Proctor, 2001). These are a combination of both host and network-based intrusion detection systems.
ANATOMY OF AN INTRUSION DETECTION SYSTEM
An intrusion detection system is basically a combination of capabilities which detect and respond to threats. This conglomerate consists of the following: a command console, a network sensor, a alert notification subsystem, a response subsystem, a database and a network tap (Proctor, 2001).
An intrusion detection system usually requires a security policy in order to work efficiently. A security policy simply defines acceptable and unacceptable activity. This is because there are certain ‘threats’ which are trivial and do not require any attention at all while others are more urgent. Once the alarm is detected, the system sends out notifications mostly in form of the following: e-mails, page, SNMP traps, and onscreen just to mention a few (Proctor, 2001). Response mechanisms due to these notifications often include: shut down a connection, shut down a computer, log off a user, disable an account, reconfigure a router/firewall, increase auditing (Proctor, 2001)..
TRADITIONAL AUDIT VERSUS INTRUSION DETECTION
There are significant differences in both the benefits and capabilities and benefits of a traditional audit system and an intrusion detection system. For instance, traditional audit is mainly concerned with the analysis of the assets of an organization while intrusion detection systems look for anomalies in the patterns of behaviour.
Integrity checkers
This refers to a class of tools that calculate the integrity seals for system objects using MD5 or a simple cyclical redundancy check (CRC) for storage in a baseline database(cite) and are usually mistaken for intrusion detectors.
There is a lot of hype about what intrusion detection is all about now and in the future but the fundamental question remains: what is detection and misuse? In concept, all misuse constitutes of an unauthorized accesses to data by an individual, an unauthorized modification to data and denial of service. The main aim of intrusion detection systems is to detect unacceptable behaviour (cite). There are two main types of detection: detecting adherence to known threat patterns and detecting deviations from acceptable behaviour (Proctor, 2001).
References
Proctor, P. E. (2001). The Practical Intrusion Detection Handbook: Chapter 1.
Pearson Education, Inc. Published by Prentice Hall.
