Infa 630 -intrusion detection and intrusion prevention-final exam

INFA 630

 Intrusion Detection and Intrusion Prevention

Final Exam

 

Instructions

 

You are to take this test during the week. Work alone. You may not confer with other class members, or anyone else, directly or by e-mail or otherwise, regarding the questions, issues, or your answers. You may use your notes, textbooks, other published materials, and Internet sources, keeping in mind your responsibility to give proper attribution to sources of material you use in your responses. Avoid using personal blogs and dotcom sites. The material on these sites generally is not peer reviewed.

 

The test is scored on the basis of 100 points for the test.

 

For the short answer section, bear in mind that a clear concise response that directly answers the question asked is always preferable to providing large volumes of potentially irrelevant information in the hope that the “right” answer will somehow be included. Too much extraneous information may cause negative impact on grade for the exam.

 

When composing your answers to the essay questions, be thorough. Do not simply examine one alternative if two or more alternatives exist. The more complete your answer, the higher your score will be. Be sure to identify any assumptions you are making in developing your answers, and describe how your answer would change if the assumptions were different. Use paragraph for different points

           

While composing your answers to the essay questions, be very careful to cite your sources with page numbers for the book. It is easy to get careless and forget to footnote a source. Remember, failure to cite sources constitutes an academic integrity violation. Use APA style for citations and references. So far I haven’t penalized for not using APA style but it may not be so for the final.

 

In preparing your exam for submission, please follow these instructions precisely:

 

1.      Use this document as a template, i.e., fill in your answers in the indicated locations.

2.      Modify the header to show your name.

3.      Submit your completed exam as a Microsoft Word or RTF document via your LEO Assignments folder no later than 11:59 p.m. Eastern Standard Time.. Late submissions are subject to a grade penalty. But let me know if you difficulty in submitting on time.

4.      Include Self Certification; failure may cause negative impact (small) on the grade.

 

Please submit questions regarding the exam to your instructor at [email protected]  If questions submitted via email are generic, your instructor will post them in a LEO Q&A conference area, without revealing their source.

 

Exam Questions

 

Part 1: True or False Questions. (10 questions at 1 point each) Add reason

 

  1. T  F      To have a Snort rule match on both inbound and outbound traffic, the rule should use the flow:to_server,from_client,established;option.          Answer: _____

Reason:_

 

 

  1. T  F      Host-based IDS can be used to monitor compliance with corporate policies such as acceptable use of computer resources.       Answer: _____

Reason:_

 

 

  1. T  F      An on-demand operational IDS model is not suitable if legally admissible data collection is required.      Answer: _____

Reason:_

 

 

  1. T  F      Current criminal and civil procedure laws and rules of evidence do not provide clear guidance on digital and electronic forms of evidence such as IDS logs.    Answer: _____

 

Reason:_

 

  1. T  F      Snort unified output plug-ins can be used to off-load computing tasks from the core Snort program to improve overall performance.    Answer: _____

 

Reason:_

 

  1. T  F      Thresholds used in Snort alert rules can cause false negatives if the attacker works slowly enough.     Answer: _____

 

Reason:_

 

  1. T  F      Network-based IDS provides no protection against internal threats.  Answer: _____

 

 

  1. T  F      When a “pass” rule is matched in Snort, no other rules are evaluated.             Answer: _____

 

Reason:_

 

  1. T  F      To ensure proper execution of Snort rules using the “uricontent” option the HTTP Inspect preprocessor must be installed and configured in Snort.   Answer: _____

 

Reason:_

 

  1. T  F      There are no monitoring situations that justify real-time intrusion response.          Answer: _____

 

Reason:_

 

 

 

 

 

Part 2: Short Answer Questions. (10 questions at 6 points each)

 

  1. False positive and False negative
    1. Define and differentiate false positive and false negative.
    2. Which is worse, and why?
    3. Give one example of each, drawn from any context that demonstrates your understanding of the terms.

 

Answer:         

                       

Reason:_

                       

  1. Snort rule
    1. Describe the components of the following Snort rule.

alert ip any any -> any any (msg:”BAD-TRAFFIC same SRC/DST”; sameip; reference:bugtraq,2666; reference:cve,1999-0016; reference:url,www.cert.org/advisories/CA-1997-28.html; classtype:bad-unknown; sid:527; rev:8;)

a.       What sort of attack is it intended to detect?

b.      What network traffic pattern information is it looking for?

 

Answer:

 

Reason:_

 

 

  1. User-centric and target-centric monitoring:
    1. What are the key differences between user-centric and target-centric monitoring in behavioral data forensics?
    2. Is one perspective preferred over the other?
    3. If so, what are some of the advantages of the preferred choice, or disadvantages of the non-preferred choice?

 

Answer:

 

Reason:_

 

 

  1. Write a rule using Snort syntax to detect an internal user executing a Windows “tracert” command to identify the network path to an external destination. What changes, if any, would you need to make to this rule to make it also work for a Unix/Linux “traceroute”? 

 

Answer:

 

Reason:_

 

  1. As Trost noted, most network IDS tools are designed to optimize performance analyzing traffic using a variety of protocols specific to TCP/IP wired networks.
    1. Describe at least two intrusion detection scenarios where specialized types of monitoring and analysis are called for
    2.  what limitations exist in conventional NIDS that make them insufficient to provide effective intrusion detection in the environments corresponding to these scenarios.

 

Answer:

 

Reason:_

 

  1. Multi-event signature
    1. What is a multi-event signature?
    2. Provide at least two examples of multi-event signature activities or patterns that might be monitored with an intrusion detection system.

 

Answer:         

 

Reason:_

 

 

  1. Anomaly-based intrusion detection
    1. What are the operational requirements necessary to perform anomaly-based intrusion detection?
    2. How does the information gathered about network traffic by anomaly-based IDS tools differ from the information gathered by signature-based NIDS?

 

Answer:         

 

Reason:_

 

 

  1. Many people perceive intrusion detection to be a constant, all-the-time security function.
    1. Identify and describe at least two “part-time” intrusion detection operational models,
    2. and for each give an example of a usage scenario that would call for part-time monitoring.

 

Answer:         

Reason:_

 

 

 

  1. Are organizations legally obligated to use intrusion detection capabilities? Why or why not?

 

Answer:         

 

 

Reason:_

 

  1. Imagine you are tasked with monitoring network communication in an organization that uses encrypted transmission channels.
    1. What are the limitations of using intrusion detection systems in this environment?
    2. What methods would you employ to accomplish this task?

 

Answer:         

 

Reason:_

 

 

 Part 3: Essay Questions. Maximum length: 2 pages each, excluding references. (Two questions at 15 points each)

 

  1. In 2003, a well-publicized report from IT analyst firm Gartner predicted that the market for stand-alone IDS tools would soon disappear, and urged Gartner clients to cease investing in IDS tools in favor of firewalls. Last week, U.S. cyber security czar Howard Schmidt publicly called for enterprise network intrusion detection, and asked, “Why haven’t we done this already?” (http://fcw.com/articles/2010/04/14/irmco-cyber-security-issues-initiatives-howard-schmidt.aspx?s=fcwdaily_150410) Clearly, the obsolescence of IDS tools by 2005 did not occur as Gartner predicted.
    1. What factors have been most important in the continued viability of the IDS market?
    2. Based on what you have learned about IDS and IPS tools, do you think these tools will continue to be used as a key security component? Why or why not?

 

 

 

  1. In early 2008, the U.S. Department of Homeland Security stated publicly that it wanted more intrusion detection capabilities, in particular citing a need to move to mandatory real-time intrusion detection for federal government networks, as an expansion of current passive, voluntary monitoring. The current manifestation of this goal is the Einstein program, which while officially in a pilot phase is likely to be expanded significantly soring in 2011. (See http://fcw.com/articles/2010/03/19/einstein-3-test-intrusion-prevention-system.aspx)
    1. Using what we have learned in this course and your own knowledge of IDS operational models, requirements, and other characteristics associated with selecting and using the most appropriate types of intrusion detection and prevention, what is your response to the proposal to implement comprehensive intrusion detection and prevention for all network traffic to or from U.S. government agencies?
    2. What are some of the key obstacles faced in rolling out an intrusion detection capability of this sort?
    3. Identify and describe at least three (3) challenges that DHS should consider when planning the Einstein deployment.

 

 

Calculate the price
Make an order in advance and get the best price
Pages (550 words)
$0.00
*Price with a welcome 15% discount applied.
Pro tip: If you want to save more money and pay the lowest price, you need to set a more extended deadline.
We know how difficult it is to be a student these days. That's why our prices are one of the most affordable on the market, and there are no hidden fees.

Instead, we offer bonuses, discounts, and free services to make your experience outstanding.
How it works
Receive a 100% original paper that will pass Turnitin from a top essay writing service
step 1
Upload your instructions
Fill out the order form and provide paper details. You can even attach screenshots or add additional instructions later. If something is not clear or missing, the writer will contact you for clarification.
Pro service tips
How to get the most out of your experience with Australia Assessments
One writer throughout the entire course
If you like the writer, you can hire them again. Just copy & paste their ID on the order form ("Preferred Writer's ID" field). This way, your vocabulary will be uniform, and the writer will be aware of your needs.
The same paper from different writers
You can order essay or any other work from two different writers to choose the best one or give another version to a friend. This can be done through the add-on "Same paper from another writer."
Copy of sources used by the writer
Our college essay writers work with ScienceDirect and other databases. They can send you articles or materials used in PDF or through screenshots. Just tick the "Copy of sources" field on the order form.
Testimonials
See why 20k+ students have chosen us as their sole writing assistance provider
Check out the latest reviews and opinions submitted by real customers worldwide and make an informed decision.
Art (Fine arts, Performing arts)
Great work!!!! I will absolutely come back. Thank you to the support team and the tutor they all did a wonderful work.
Customer 454055, February 18th, 2020
English 101
She did an excellent job on my revision
Customer 464103, April 24th, 2023
Healthcare & Medical
Good work
Customer 463469, October 22nd, 2022
Medicine
Great job.
Customer 462457, April 28th, 2022
Military
Good job
Customer 456821, January 2nd, 2023
Other
Good job
Customer 456821, December 26th, 2022
Philosophy
Thank you for helping me with such a hard and sad topic. I found it very hard to write and be partial and fair state of mind. In the paper you pointed out points that I had missed. Thank you again!
Customer 463465, January 9th, 2023
Medicine
The writer has a good content
Customer 463147, December 28th, 2022
Nursing
2 hrs late
Customer 454007, April 12th, 2020
Military
Good job
Customer 456821, January 11th, 2023
Sociology
Really beautiful, beautiful work here. Well done! I love this service so much!
Customer 454259, April 11th, 2020
Business and administrative studies
Thank you!
Customer 453187, April 3rd, 2022
11,595
Customer reviews in total
96%
Current satisfaction rate
3 pages
Average paper length
37%
Customers referred by a friend
OUR GIFT TO YOU
15% OFF your first order
Use a coupon FIRST15 and enjoy expert help with any task at the most affordable price.
Claim my 15% OFF Order in Chat