|
50 ways to defeat your Intrusion Detection System
By Fred Cohen & Associates
Advanced
Perimeter Detection and Defense
How can you tell whether your system has been compromised, and
what do you do if it has? If you are running a Windows NT or
2000 Web server with Microsoft IIS 4 or 5, this article will
show you how to tighten perimeter security with automated
tracking and detection techniques. Source: 8 Wire (Jan
31, 2001)
Anatomy of an Intrusion
A great eye-opening article on Intrusions by Greg Shipley, Source: Network Computing's Security Workshop, (Oct 1999)
Can Intrusion Detection Keep an Eye on Your Network's Security?
Catching network and host attacks as they happen isn't always possible with firewalls and other security tools. Intrusion detection can be your eyes and ears throughout the enterprise. Source: Network Magazine (April 1999)
Computer
Crime Investigators Toolkit
A 4 part series that devises a summary of basic,
practical knowledge, "tricks," if you like, that
should interest all computer crime investigators. While they
may not be the final word in preparing for an examination,
these techniques will provide some insight into the ways and
means of computer criminals. Source: EarthWeb
Cracker Tracking: Tighter Security with Intrusion Detection
An Article in BYTE Magazine by Michael Hurwicz. Discusses the differences between host and network based detection systems and does a brief comparison of some of the major products on the market.
Computer Security Incident Handling: Step-by-Step
Advice on how to respond to break-ins and hacker attacks. Source: SANS.org
Data Mining Approaches for Intrusion Detection
An interesting whitepaper from Columbia University's Computer Science Department
DDOS attacks' ultimate lesson: Secure that infrastructure
By following best of breed security practices, many an e-business could at the least minimize their downtime to 10-15
minutes instead of the 2-4 hour lapses that occurred in the February DDOS attacks on Amazon, Yahoo and e-Bay. Source EarthWeb
(Sept 14, 2000)
Detecting unauthorized access with Microsoft Proxy Server
Keep watch for intruders through some of the built-in Proxy Server settings in Microsoft BackOffice. Source EarthWeb (May
12, 2000)
Detecting Signs of Intrusion
From CERT at Carnegie Mellon University
Fast Path to Intrusion Detection and Event Logging
Most network administrators will face a computer
security intrusion event sometime during their
careers. Having an intrusion detection plan will
result in earlier intrusion notification, minimize
the consequences, and allow a quicker recovery.
Microsoft provides several tools for intrusion
detection, including event logging. This document
will discuss intrusion detection and some of the
Microsoft tools that you can use as part of an
intrusion detection plan. Source:
Microsoft Technet
Hacker Alert - Intrusion Detection Software is hot , but can it really stop Hacker's cold?
A hard look at what options are out there, and how they actually function in the real world, Source: Network World, (Sept 27, 1999)
HOW TO: Configure Performance Counters and Logs to Monitor
Unauthorized Attempts to Access Your Computer in Windows 2000
Server
Microsoft Knowledge Base Article 300504 - This step-by-step
article describes how to use the Performance Logs and Alerts
service to create counter logs and alerts to monitor
unauthorized attempts to access your computer in Microsoft
Windows 2000 Server.
HOW TO: Enable and Apply Security Auditing in Windows 2000
Microsoft Knowledge Base Article Q300549 - This step-by-step
instruction guide describes how to enable and apply Windows
security auditing.
HOW TO: Enable Local Security Auditing in Windows 2000
Microsoft Knowledge Base Article Q248260 - This article
describes how to enable local security auditing in Windows 2000.
Administrators of local computers can use this method to set up
local auditing of security access rights on individual Windows
2000-based computers.
HOW TO: Enable Active Directory Access Auditing in Windows 2000
Microsoft Knowledge Base Article Q314977 - This step-by-step
article describes how to enable Active Directory access auditing
in Windows 2000. The Active Directory should be audited to
assess when authorized and unauthorized access is attempted. You
can configure auditing of the Active Directory database. After
you enable auditing, you can view the audit information in the
Directory Service log that is located in the Event Viewer. Note
that this log is only present on computers that are acting as
Active Directory domain controllers. This article describes how
you can enable Active Directory for auditing access.
How to Enable User Environment Event Logging in Windows 2000
Microsoft Knowledge Base Article Q186454 - This article describes how to enable the user environment event logging features available in Windows 2000.
HOW TO: Monitor for Unauthorized User Access in Windows 2000
Microsoft Knowledge Base Article Q300958 - This article describes how to monitor your system for unauthorized user access. There are two main steps: Enabling security auditing and viewing the security logs.
Note that different systems have different security needs, and
the security topic is complex. Any user who sets up security
audits on your system must be assigned to administrative groups
or be given security rights and privileges.
Immediate
intrusion detection: Catching hackers red-handed on your web
server!
This white paper focuses on how administrators can set
up their web servers successfully and safely. Describing the
tools used by hackers to gain backdoor access to your IIS web
servers, this paper details the necessary steps to detect
successful intrusions on your network, as well as explaining how
to prevent such attacks to your web server. Source: GFI.com
Incident Handling
A little planning goes a long way when handling computer break-ins. Source: Network Magazine (Jan 2000)
Intrusion Detection Tools to stop hackers cold
A review of host based monitoring and network based scanners by Ellen Messmer. Source: Network World,
(2/15/99)
Intrusion Detection: The Guard Inside the Gate
A firewall puts a lock on the door. IDS is the watchdog inside.
Source EarthWeb (Oct 30, 2000)
Intrusion Today
A small news archive from the NetworkICE corporation
Intrusion Detection and Response
A whitepaper on the viability of Intrusion Detection Systems from National Info-Sec at the Lawrence Livermore National Laboratories
Intrusion Detection provides a pound of prevention
Article by Mark Abene in Network Computing's Security Workshop, August 1997
Intrusion Detection Take 2
A second look at intrusion-detection systems shows that a combination of network-based and host-based technologies is a promising strategy. But is it ready to safeguard your network?
Source: Network Computing (Nov 1999)
Passive Network Traffic Analysis: Understanding a
Network Through Passive Monitoring
This article will offer a brief overview of passive
network monitoring, which can offer a thorough
understanding of the network's topology: what
services are available, what operating systems are
in use, and what vulnerabilities may be exposed on
the network. Source: SecurityFocus
Life After IDS
You spent months evaluating, testing, purchasing and deploying your intrusion detection system. Now the fun really begins. Source: Information Security Magazine (September 1999)
Log-based
intrusion-detection and -analysis in Windows 2000/NT
This white paper demonstrates that the audit and
reporting facilities in Microsoft Windows NT and Microsoft
Windows 2000, although a good foundation, fall far short of
fulfilling real-life business needs. Therefore, the need exists
for a log-based intrusion-detection and -analysis tools. Source:
GFI.com
Personal Firewalls/Intrusion Detection
The complexity of PC operating systems, applications and browsers has contributed to continual discovery of security weaknesses (which the typical user cannot be expected to follow or understand). Until now the standard tool for defending Windows was the Anti-Virus scanner, but this
is no longer enough - the Personal Firewall has made its debut and should soon become an essential tool for Windows users connected to hostile networks. Source: Security Portal (July 17, 2000)
Preventing
and Detecting Insider Attacks Using IDS
Insider attacks pose unique challenges for security
administrators. This article will examine some ways
in which intrusion detection systems can be used to
help prevent and detect insider attacks. Source: SecurityFocus.com
Responding to Intrusions
From CERT at Carnegie Mellon University
Security Reality Check
Intrusion detection spots bad things happening in your network?..sometimes. Source: Network Magazine (July 1999)
Sniffing out Network Intruders
A Product comparison and introduction to Network Sniffer programs Source: InfoWorld's Test Center. (Feb 1999)
Spotting Intruders
A great article by Brian Robinson. Source: Federal Computer Week, March 1999
To Catch an Internet Thief
Tracking intruders back to their lairs may require an Internet posse. Source: Network Magazine (Feb 1999)
Working with the NT Security Log
By Paul E. Proctor, Windows NT Systems Magazine, Sept 1997 |