Intrusion Detection Systems
Installing Antivirus Software on Personal Computers
1. Introduce the terms antivirus software and virus signature.
2. Introduce the class to the United States Computer Emergency Readiness Team
Teaching
Tip
Emphasize that virus detection is based on a rule-based approach that looks for
definitions of known viruses. As new viruses are written, the virus detection
software must be updated with the new definitions in order to be effective.
Implementing Safeguards against Attacks by Malicious Insiders
1. Note that the prompt deletion of computer accounts, login IDs, and passwords of
2. Point out that an important safeguard is to create roles and user accounts so that users
have the authority to perform their responsibilities and nothing more.
Defending Against Cyberterrorism
1. In the face of increasing risks of cyberterrorism, organizations need to be aware of the
Addressing the Most Critical Internet Security Threats
1. US-CERT regularly updates a summary of the most frequent, high-impact
Conducting Periodic IT Security Audits
1. Introduce the term security audit.
2. Explain that a thorough security audit should test system safeguards to ensure that they
are operating as intended. Such tests might include trying the default system
passwords that are active when software is first received from the vendor.
Quick Quiz 3
1. The concept of _____ recognizes that managers must use their judgment to ensure that the
cost of control does not exceed the system’s benefits or the risks involved.
2. A(n) _____ defines an organization’s security requirements, as well as the controls and
sanctions needed to meet those requirements.
3. A(n) _____ works by using the Internet to relay communications; it maintains privacy
through security procedures and tunneling protocols, which encrypt data at the sending end
and decrypt it at the receiving end.
4. A(n) _____ works to prevent an attack by blocking viruses, malformed packets, and other
threats from getting into the protected network.
E. Detection
1. Even when preventive measures are implemented, no organization is completely secure
from a determined attack. Thus, organizations should implement detection systems to
catch intruders in the act.
2. Introduce the term intrusion detection system.
Teaching
Tip
Discuss the pros and cons of knowledge-based approaches compared to
behavior-based approaches, noting that knowledge-based approaches can be
brittle, and behavior-based approaches can be inaccurate.
F. Response
1. An organization should be prepared for the worst— – a successful attack that defeats all
or some of a system’s defenses and damages data and information systems.
Teaching
Tip
Discuss situations in which it would, or would not, be desirable to track down
an attacker and prosecute him.
Incident Notification
1. Explain that a key element of any response plan is to define who to notify and who not
to notify. Questions to cover include the following: Within the company, who needs to
be notified, and what information does each person need to have? Under what
Teaching
Tip
Discuss reasons why the information about a security compromise should not
be released publicly.
Protection ofProtecting Evidence and Activity Logs
1. An organization should document all details of a security incident as it works to
resolve the incident. Explain that documentation captures valuable evidence for a
Incident Containment
1. Point out that the response plan should clearly define the process for deciding if an
attack is dangerous enough to warrant shutting down or disconnecting critical systems
from the network.
Eradication
1. Before the IT security group begins the eradication effort, it must collect and log all
possible criminal evidence from the system, and then verify that all backups are
current, complete, and free of any virus.
Incident Follow-up
1. Explain that a review should be conducted after an incident to determine exactly what
happened and to evaluate how the organization responded. One approach is to write a
formal incident report that includes a detailed chronology of events and the impact of
the incident.
2. Note that the creating a detailed chronology of all events will also document the
Computer Forensics
1. Computer forensics is a discipline that combines elements of law and computer
science to identify, collect, examine, and preserve data from computer systems,
networks, and storage devices in a manner that preserves the integrity of the data
gathered so that it is admissible as evidence in a court of law. Explain that a computer
forensics investigation may be opened in response to a criminal investigation or civil
litigation.
Quick Quiz 4
1. A(n) _____ software and/or hardware that monitors system and network resources and
activities, and notifies network security personnel when it identifies possible intrusions from
outside the organization or misuse from within the organization.
2. _____ is a discipline that combines elements of law and computer science to identify,
collect, examine, and preserve data from computer systems, networks, and storage devices in
a manner that preserves the integrity of the data gathered so that it is admissible as evidence
in a court of law.
3. (True or False) A behavior-based intrusion detection system models normal behavior of a
system and its users from reference information collected by various means.
Discussion Questions
1. If known vulnerabilities in software are entry points for an attacker, why are the software
vulnerabilities not corrected before the software is released?
2. Should hackers be hired by companies to identify system vulnerabilities?
Additional Projects
1. Design a security education program for employees.
2. Write a paper about the I LOVEYOU worm, including an analysis of why it spread as
quickly and widely as it did, and preventative steps that could have been taken.
3. Write an essay discussing the pros and cons of hiring known hackers to test the security of a
system.
Additional Resources
Key Terms
Antivirus software: Scans a computers memory and disk drives regularly for viruses
Botnet: Large group of computers controlled from one or more remote locations by
hackers, without the knowledge or consent of their owners
Bring your own device (BYOD): Business policy that permits, and in some cases
encourages, employees to use their own mobile devices (smartphones, tablets, or laptops)
to access company computing resources and applications, including email, corporate
databases, the corporate intranet, and the Internet
CAPTCHA: Software that generates and grades tests that humans can pass but all but the
most sophisticated computer programs cannot
Cloud computing: An environment in which software and data storage are services
provided via the Internet (the cloud); the services are run on another organization’s
computer hardware and are accessed by a Web browser
Collusion: Fraud committed by an employee in cooperation with a person outside of the
organization
Competitive intelligence: Legally obtained information gathered using sources available
to the public; used to help a company gain an advantage over its rivals
Computer forensics: Discipline that combines elements of law and computer science to
identify, collect, examine, and preserve data from computer systems, networks, and storage
Cyberterrorist: A hacker that intimidates or coerces a government or organization to
advance a political or social objective by launching computer-based attacks against other
computers
Data breach: The unintended release of sensitive data or the access of sensitive data by
unauthorized individuals
E-mail spam: The abuse of e-mail systems to send unsolicited e-mail to large numbers of
people
Hacker: A computer programmer who tests the limitations of a system out of intellectual
curiosity
Hacktivism: A combination of the words hacking and activism, is hacking to achieve a
political or social goal
Industrial espionage: Involves using illegal means to obtain information that is not
available to the public
Industrial spy: Insider in an organization who uses illegal means to obtain trade secrets
from competitors of his or her firm
Intrusion detection system (IDS): Monitors system and network resources and activities,
and then notifies the proper authority when it identifies possible intrusions
Intrusion prevention systems (IPS)—prevents an attack by blocking viruses, malformed
packets, and other threats from getting into the protected network. Lamer: A derogatory
Ransomware—malware that disables a computer or smartphone until the victim pays a
fee, or ransom
Reasonable assurance: A concept that recognizes that managers must use their judgment
to ensure that the cost of control does not exceed the system’s benefits or the risks involved
Risk assessment: An organization’s review of potential threats to its computers and
network and the probability of those threats occurring
Rootkit: Set of programs that enables its user to gain administrator level access to a
computer without the end users consent or knowledge
Script kiddy: A derogatory term for a hacker with poor skills, used by hackers with better
skills
Security audit: Evaluates whether an organization has a well-considered security policy in
place and if it is being followed
Security policy: Defines an organization’s security requirements and the controls and
sanctions needed to meet those requirements
Smart card: A credit card that contains a memory chip that is updated with encrypted data
every time the card is used
Smishing: A variation of phishing in which victims receive a legitimate-looking SMS text
message on their phone telling them to call a specific phone number or to log on to a Web
site
computing experiences based on sound business practices
Virtual private network (VPN): Uses the Internet to relay communications and maintains
privacy through security procedures and tunneling protocols, which encrypt data at the
sending end and decrypt it at the receiving end
Virtualization software: A software program that emulates computer hardware by
enabling multiple operating systems to run on one computer host
Virus: A piece of programming code, usually disguised as something else, that causes
some unexpected and usually undesirable event
Virus signature: A specific sequence of bytes indicative of a virus