★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/intrusion_detection_article-4104.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Intrusion Detection 12/3/2001 20:32

SANS Intrusion Detection FAQ

SANS
Posted By: Dave Wreski
12/3/2001

This document provides a great starting point for those interested in intrusion detection. "ID stands for Intrusion Detection, which is the art of detecting inappropriate, incorrect, or anomalous activity. ID systems that operate on a host to detect malicious activity on that host are called host-based ID systems, and ID systems that operate on network data flows are called network-based ID systems.

Sometimes, a distinction is made between misuse and intrusion detection. The term intrusion is used to describe attacks from the outside; whereas, misuse is used to describe an attack that originates from the internal network. However, most people don't draw such distinctions.


Click here to go to this article.

Linux Advisory Watch - December 14th 2001
Dec 14

Casual PKI and making e-mail encryption easy
Dec 13

Russian Hacker Charges Dropped
Dec 13

NIPC urges heightened attention to domain name servers
Dec 13

cDc on FBIs Magic Lantern: The Real Story
Dec 13

Tool of the Month: Vipul's Razor
Dec 13

Incident Management with Law Enforcement
Dec 13

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000