* 13 *
Intrusion detection
Graded problems
The purpose of these exercises is to familiarize you with some of the
concepts of intrusion detection. Unfortunately we do not have the time
or the resources to set up intrusion detectors personally.
- Create a cause tree for intrusion detection at a site, which
includes network traffic and changes to host (Hint, think about
use of MD5 checksums of files, logging and analysis of data etc.).
- Use nmap to port scan a few machines at IU (e.g. cube).
On an avergae day you will find a number of unidentifiable ports
open. These are usually IRC related services which students run
"illegally".
Do not portscan anywhere outside our College. Portscans are usually
regarded as attacks!.
- Snort is a so-called intrusion detection
system (IDS) which logs network traffic and attempts to match patterns of
events to a knowledge-base of known attacks. Such intrusion detection systems
generate enormous amounts of data. Some example data have been
collected at cube:/local/iu/var_log_snort from about ten minutes of
watching on a private branch of a switched network.
- Examine the files and sub-directories. There are many directories
here. What do they represent?
- In the file called alert, there is chronological summary
of possible problems. Some of these have explanatory references at
whitehats.com. Do you think that all of these alerts correspond to real
attacks?
- What do you think is the main problem for intrusion detection systems?
- The final graded problem is for you to evaluate the course.
Please answer the following questions as part of your final
submission, to be delivered next week.
- Hvor vellykket mener du at kurset har vært i
- Å vise deg hva datasikkerhet går ut på
- Å få deg til å innse hvordan sikkerhets mekanismer fungerer i detalj.
- Å få deg til å unngå de verste software feil selv.
- Hvordan vurderer du kontinuiteten mellom dette og andre fag?
- Har forelesningene vært tilstrekkelige? Burde det vært flere?
- Har øvingsoppgavene vært tilstrekkelige?
- Opplever du en passe blanding av teori og praksis i kurset?
- Hvordan vurderer du kontinuiteten i forelesningene?
- Har du hele tiden skjønt poenget med de valgte emnene i forelesningene?
- Har du hele tiden skjønt poenget med ukeoppgavene?
- Hva synes du om boka?
- Har du hele tiden fått svar på det du lurte på?
- Har du inntrykk av at du lærer noe i kurset?
- Hva oppfatter du som det viktigste en kan lære av et kurs i datasikkerhet?
- Hva synes du er det beste med kurset?
- Hva synes du er det dårligste med kurset?
- Hva synes du burde vært anderledes?
- Generelle kommentarer eller inntrykk?