<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>secercah cahaya</title>
	<atom:link href="http://ksatriamatahari.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://ksatriamatahari.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Mon, 30 Jun 2008 20:46:10 +0000</lastBuildDate>
	<language>id</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='ksatriamatahari.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>secercah cahaya</title>
		<link>http://ksatriamatahari.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://ksatriamatahari.wordpress.com/osd.xml" title="secercah cahaya" />
	<atom:link rel='hub' href='http://ksatriamatahari.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Application protocol-based intrusion detection system</title>
		<link>http://ksatriamatahari.wordpress.com/2008/06/30/application-protocol-based-intrusion-detection-system/</link>
		<comments>http://ksatriamatahari.wordpress.com/2008/06/30/application-protocol-based-intrusion-detection-system/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 20:38:39 +0000</pubDate>
		<dc:creator>ksatriamatahari</dc:creator>
				<category><![CDATA[computer science]]></category>

		<guid isPermaLink="false">http://ksatriamatahari.wordpress.com/?p=7</guid>
		<description><![CDATA[An application protocol-based intrusion detection system (APIDS) is an intrusion detection system that focuses its monitoring and analysis on a specific application protocol or protocols in use by the computing system. An APIDS will monitor the dynamic behavior and state of the protocol and will typically consist of a system or agent that would typically [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=7&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>An <strong>application protocol-based intrusion detection system (APIDS)</strong> is an <a title="Intrusion detection system" href="http://en.wikipedia.org/wiki/Intrusion_detection_system">intrusion detection system</a> that focuses its monitoring and analysis on a specific application <a title="Protocol (computing)" href="http://en.wikipedia.org/wiki/Protocol_%28computing%29">protocol</a> or protocols in use by the computing system.</p>
<p>An APIDS will monitor the dynamic behavior and <a title="State (computer science)" href="http://en.wikipedia.org/wiki/State_%28computer_science%29">state</a> of the protocol and will typically consist of a system or agent that would typically sit between a <a title="Process (computing)" href="http://en.wikipedia.org/wiki/Process_%28computing%29">process</a>, or group of <a title="Server (computing)" href="http://en.wikipedia.org/wiki/Server_%28computing%29">servers</a>, <a title="Monitoring" href="http://en.wikipedia.org/wiki/Monitoring">monitoring</a> and analyzing the application protocol between two connected devices.</p>
<p>A typical place for an APIDS would be between a <a title="Web server" href="http://en.wikipedia.org/wiki/Web_server">web server</a> and the <a title="Database management system" href="http://en.wikipedia.org/wiki/Database_management_system">database management system</a>, monitoring the <a title="SQL" href="http://en.wikipedia.org/wiki/SQL">SQL</a> protocol specific to the <a title="Middleware" href="http://en.wikipedia.org/wiki/Middleware">middleware</a>/<a title="Business logic" href="http://en.wikipedia.org/wiki/Business_logic">business logic</a> as it interacts with the <a title="Database" href="http://en.wikipedia.org/wiki/Database">database</a>.</p>
<p>At a basic level an APIDS would look for, and enforce, the correct (legal) use of the protocol.</p>
<p>However at a more advanced level the APIDS can learn, be taught or even reduce what is often an infinite protocol set, to an acceptable understanding of the <a title="Subset" href="http://en.wikipedia.org/wiki/Subset">subset</a> of that application protocol that is used by the application being monitored/protected.</p>
<p>Thus, an APIDS, correctly configured, will allow an application to be &#8220;<a title="Fingerprint" href="http://en.wikipedia.org/wiki/Fingerprint">fingerprinted</a>&#8220;, thus should that application be subverted or changed, so will the fingerprint change.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ksatriamatahari.wordpress.com/7/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ksatriamatahari.wordpress.com/7/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ksatriamatahari.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ksatriamatahari.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ksatriamatahari.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ksatriamatahari.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ksatriamatahari.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ksatriamatahari.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ksatriamatahari.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ksatriamatahari.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ksatriamatahari.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ksatriamatahari.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ksatriamatahari.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ksatriamatahari.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ksatriamatahari.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ksatriamatahari.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=7&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ksatriamatahari.wordpress.com/2008/06/30/application-protocol-based-intrusion-detection-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/20938f951cbc61a845d66b15e895fa30?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ksatriamatahari</media:title>
		</media:content>
	</item>
		<item>
		<title>Protocol-based intrusion detection system</title>
		<link>http://ksatriamatahari.wordpress.com/2008/06/30/protocol-based-intrusion-detection-system/</link>
		<comments>http://ksatriamatahari.wordpress.com/2008/06/30/protocol-based-intrusion-detection-system/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 20:37:23 +0000</pubDate>
		<dc:creator>ksatriamatahari</dc:creator>
				<category><![CDATA[computer science]]></category>

		<guid isPermaLink="false">http://ksatriamatahari.wordpress.com/?p=6</guid>
		<description><![CDATA[A protocol-based intrusion detection system (PIDS) is an intrusion detection system which is typically installed on a web server, and is used in the monitoring and analysis of the protocol in use by the computing system. A PIDS will monitor the dynamic behavior and state of the protocol and will typically consist of a system [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=6&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A <strong>protocol-based intrusion detection system (PIDS)</strong> is an <a title="Intrusion detection system" href="http://en.wikipedia.org/wiki/Intrusion_detection_system">intrusion detection system</a> which is typically installed on a <a title="Web server" href="http://en.wikipedia.org/wiki/Web_server">web server</a>, and is used in the monitoring and analysis of the <a title="Communications protocol" href="http://en.wikipedia.org/wiki/Communications_protocol">protocol</a> in use by the computing system. A PIDS will monitor the dynamic behavior and state of the protocol and will typically consist of a system or agent that would typically sit at the front end of a server, monitoring and analyzing the communication between a connected device and the system it is protecting.</p>
<p>A typical use for a PIDS would be at the front end of a web server monitoring the <a class="mw-redirect" title="HTTP" href="http://en.wikipedia.org/wiki/HTTP">HTTP</a> (or <a class="mw-redirect" title="HTTPS" href="http://en.wikipedia.org/wiki/HTTPS">HTTPS</a>) protocol stream. Because it understands the HTTP protocol relative to the web server/system it is trying to protect it can offer greater protection than less in-depth techniques such as filtering by <a title="IP address" href="http://en.wikipedia.org/wiki/IP_address">IP address</a> or <a class="mw-redirect" title="Port number" href="http://en.wikipedia.org/wiki/Port_number">port number</a> alone, however this greater protection comes at the cost of increased computing on the web server.</p>
<p>Where HTTPS is in use then this system would need to reside in the &#8220;shim&#8221; or interface between where HTTPS is <a title="Cryptography" href="http://en.wikipedia.org/wiki/Cryptography">un-encrypted</a> and immediately prior to it entering the Web <a title="Presentation layer" href="http://en.wikipedia.org/wiki/Presentation_layer">presentation layer</a>.</p>
<p><a id="Monitoring_dynamic_behavior" name="Monitoring_dynamic_behavior"></a></p>
<h3><span class="mw-headline">Monitoring dynamic behavior</span></h3>
<p>At a basic level a PIDS would look for, and enforce, the correct use of the protocol.</p>
<p>At a more advanced level the PIDS can learn or be taught acceptable constructs of the protocol, and thus better detect anomalous behavior.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ksatriamatahari.wordpress.com/6/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ksatriamatahari.wordpress.com/6/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ksatriamatahari.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ksatriamatahari.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ksatriamatahari.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ksatriamatahari.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ksatriamatahari.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ksatriamatahari.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ksatriamatahari.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ksatriamatahari.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ksatriamatahari.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ksatriamatahari.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ksatriamatahari.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ksatriamatahari.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ksatriamatahari.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ksatriamatahari.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=6&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ksatriamatahari.wordpress.com/2008/06/30/protocol-based-intrusion-detection-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/20938f951cbc61a845d66b15e895fa30?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ksatriamatahari</media:title>
		</media:content>
	</item>
		<item>
		<title>Host-based intrusion detection system</title>
		<link>http://ksatriamatahari.wordpress.com/2008/06/30/host-based-intrusion-detection-system/</link>
		<comments>http://ksatriamatahari.wordpress.com/2008/06/30/host-based-intrusion-detection-system/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 20:36:21 +0000</pubDate>
		<dc:creator>ksatriamatahari</dc:creator>
				<category><![CDATA[computer science]]></category>

		<guid isPermaLink="false">http://ksatriamatahari.wordpress.com/?p=5</guid>
		<description><![CDATA[A host-based intrusion detection system (HIDS) is an intrusion detection system that monitors and analyzes the internals of a computing system rather than on its external interfaces (as a network-based intrusion detection system (NIDS) would do). Host-Based IDS&#8217;s monitor all or parts of the dynamic behavior and of the state of a computer system. Much [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=5&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A <strong>host-based intrusion detection system</strong> (<strong>HIDS</strong>) is an <a title="Intrusion detection system" href="http://en.wikipedia.org/wiki/Intrusion_detection_system">intrusion detection system</a> that monitors and analyzes the internals of a computing system rather than on its external interfaces (as a <a title="Network intrusion detection system" href="http://en.wikipedia.org/wiki/Network_intrusion_detection_system">network-based intrusion detection system</a> (NIDS) would do).</p>
<p>Host-Based IDS&#8217;s monitor all or parts of the dynamic behavior and of the state of a computer system. Much as a NIDS will dynamically inspect network packets, a HIDS might detect which program accesses what resources and assure that (say) a word-processor hasn&#8217;t suddenly and inexplicably started modifying the system password-database. Similarly a HIDS might look at the state of a system, its stored information, whether in <a class="mw-redirect" title="Random Access Memory" href="http://en.wikipedia.org/wiki/Random_Access_Memory">RAM</a>, in the file-system, log files or elsewhere; and check that the contents of these appear as expected.</p>
<p>One can think of a HIDS as an <a title="Software agent" href="http://en.wikipedia.org/wiki/Software_agent">agent</a> that monitors whether anything/anyone &#8211; internal or external &#8211; has circumvented the <a title="Security policy" href="http://en.wikipedia.org/wiki/Security_policy">security policy</a> that the <a title="Operating system" href="http://en.wikipedia.org/wiki/Operating_system">operating system</a> tries to enforce.</p>
<p><a id="Monitoring_dynamic_behavior" name="Monitoring_dynamic_behavior"></a></p>
<h3><span class="mw-headline">Monitoring dynamic behavior</span></h3>
<p>Many computer users have encountered tools that monitor dynamic system behavior in the form of <a class="mw-redirect" title="Anti-virus software" href="http://en.wikipedia.org/wiki/Anti-virus_software">anti-virus</a> (AV) packages. While AV programs often also monitor system state, they do spend a lot of their time looking at who is doing what inside a computer &#8211; and whether a given program should or should not access one or another system resource. The lines become very blurred here, as many of the tools overlap in functionality.</p>
<p><a id="Monitoring_state" name="Monitoring_state"></a></p>
<h3><span class="mw-headline">Monitoring state</span></h3>
<p>The principle of operation of a HIDS depends on the fact that successful intruders (<a title="Cracking" href="http://en.wikipedia.org/wiki/Cracking">crackers</a>) will generally leave a trace of their activities. (In fact, such intruders often want to <em>own</em> the computer they have attacked, and will establish their &#8220;ownership&#8221; by installing software that will grant the intruders future access to carry out whatever activity (<a title="Keystroke logging" href="http://en.wikipedia.org/wiki/Keystroke_logging">keystroke logging</a>, <a title="Identity theft" href="http://en.wikipedia.org/wiki/Identity_theft">identity theft</a>, <a class="mw-redirect" title="Spamming" href="http://en.wikipedia.org/wiki/Spamming">spamming</a>, <a title="Botnet" href="http://en.wikipedia.org/wiki/Botnet">botnet activity</a>, <a title="Spyware" href="http://en.wikipedia.org/wiki/Spyware">spyware-usage</a> etc.) they envisage.</p>
<p>In theory, a computer user has the ability to detect any such modifications, and the HIDS attempts to do just that and reports its findings.</p>
<p>Ideally a HIDS works in conjunction with a NIDS, such that a HIDS finds anything that slips past the NIDS.</p>
<p>Ironically, most successful intruders, on entering a target machine, immediately apply best-practice security techniques to secure the system which they have infiltrated, leaving only their own <a title="Backdoor (computing)" href="http://en.wikipedia.org/wiki/Backdoor_%28computing%29">backdoor</a> open, so that other intruders can not take over <em>their</em> computers. (Crackers are a <a title="Competition" href="http://en.wikipedia.org/wiki/Competition">competitive</a> bunch&#8230;) Again, one can detect (and learn from) such changes.</p>
<p><a id="Technique" name="Technique"></a></p>
<h4><span class="mw-headline">Technique</span></h4>
<p>In general a HIDS uses a <a title="Database" href="http://en.wikipedia.org/wiki/Database">database</a> (object-database) of system objects it should monitor &#8211; usually (but not necessarily) file-system objects. A HIDS could also check that appropriate regions of memory have not been modified, for example &#8211; the system-call table comes to mind for <a title="Linux" href="http://en.wikipedia.org/wiki/Linux">Linux</a>, and various <a title="Virtual method table" href="http://en.wikipedia.org/wiki/Virtual_method_table">vtable</a> structures in <a title="Microsoft Windows" href="http://en.wikipedia.org/wiki/Microsoft_Windows">Microsoft Windows</a>.</p>
<p>For each object in question a HIDS will usually remember its attributes (permissions, size, modifications dates) and create a <a title="Checksum" href="http://en.wikipedia.org/wiki/Checksum">checksum</a> of some kind (an <a title="MD5" href="http://en.wikipedia.org/wiki/MD5">MD5</a>, <a class="mw-redirect" title="SHA1" href="http://en.wikipedia.org/wiki/SHA1">SHA1</a> hash or similar) for the contents, if any. This information gets stored in a secure database for later comparison (checksum-database).</p>
<p>An alternate method to HIDS would be to provide NIDS type functionality at the network interface (NIC) level of an end-point (either server, workstation or other end device). Providing HIDS at the network layer has the advantage of providing more detailed logging of the source of the attack (Source IP address) and attack details (packet data), neither of which a dynamic behavioral monitoring approach could see.</p>
<p><a id="Operation" name="Operation"></a></p>
<h4><span class="mw-headline">Operation</span></h4>
<p>At installation time &#8211; and whenever any of the monitored objects change legitimately &#8211; a HIDS must initialise its checksum-database by scanning the relevant objects. Persons in charge of computer security need to control this process tightly in order to prevent intruders making un-authorized changes to the database(s). Such initialization thus generally takes a long time and involves <a title="Cryptography" href="http://en.wikipedia.org/wiki/Cryptography">cryptographically</a> locking each monitored object and the checksum databases or worse. Because of this, manufacturers of HIDS usually construct the object-database in such a way that makes frequent updates to the checksum database unnecessary.</p>
<p>Computer systems generally have many dynamic (frequently changing) objects which intruders want to modify &#8211; and which a HIDS thus should monitor &#8211; but their dynamic nature makes them unsuitable for the checksum technique. To overcome this problem, HIDS employ various other detection techniques: monitoring changing file-attributes, log-files that decreased in size since last checked, and a raft of other means to detect unusual events.</p>
<p>Once a system administrator has constructed a suitable object-database &#8211; ideally with help and advice from the HIDS installation tools &#8211; and initialized the checksum-database, the HIDS has all it requires to scan the monitored objects regularly and to report on anything that may appear to have gone wrong. Reports can take the form of logs, e-mails or similar.</p>
<p><a id="Protecting_the_HIDS" name="Protecting_the_HIDS"></a></p>
<h3><span class="mw-headline">Protecting the HIDS</span></h3>
<p>A HIDS will usually go to great lengths to prevent the object-database, checksum-database and its reports from any form of tampering. After all, if intruders succeed in modifying any of the objects the HIDS monitors, nothing can stop such intruders from modifying the HIDS itself &#8211; unless security administrators take appropriate precautions. Many <a title="Computer worm" href="http://en.wikipedia.org/wiki/Computer_worm">worms</a> and <a title="Computer virus" href="http://en.wikipedia.org/wiki/Computer_virus">viruses</a> will try to disable anti-virus tools, for example.</p>
<p>Apart from crypto-techniques, HIDS might allow administrators to store the databases on a <a title="CD-ROM" href="http://en.wikipedia.org/wiki/CD-ROM">CD-ROM</a> or on other read-only memory devices (another factor militating for infrequent updates&#8230;) or storing them in some off-system memory. Similarly, a HIDS will often send its logs off-system immediately &#8211; in some instances via one-way communications channels, such as a serial port which only has &#8220;Transmit&#8221; connected, for example.</p>
<p>One could argue that the <a class="mw-redirect" title="Trusted platform module" href="http://en.wikipedia.org/wiki/Trusted_platform_module">trusted platform module</a> comprises a type of HIDS. Although its scope differs in many ways from that of a HIDS, fundamentally it provides a means to identify whether anything/anyone has tampered with a portion of a computer. Architecturally this provides the ultimate (at least <a class="mw-redirect" title="As of 2005" href="http://en.wikipedia.org/wiki/As_of_2005">at this point in time</a>) host-based intrusion detection, as depends on hardware external to the <a title="Central processing unit" href="http://en.wikipedia.org/wiki/Central_processing_unit">CPU</a> itself, thus making it that much harder for an intruder to corrupt its object and checksum databases .</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ksatriamatahari.wordpress.com/5/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ksatriamatahari.wordpress.com/5/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ksatriamatahari.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ksatriamatahari.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ksatriamatahari.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ksatriamatahari.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ksatriamatahari.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ksatriamatahari.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ksatriamatahari.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ksatriamatahari.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ksatriamatahari.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ksatriamatahari.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ksatriamatahari.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ksatriamatahari.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ksatriamatahari.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ksatriamatahari.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=5&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ksatriamatahari.wordpress.com/2008/06/30/host-based-intrusion-detection-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/20938f951cbc61a845d66b15e895fa30?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ksatriamatahari</media:title>
		</media:content>
	</item>
		<item>
		<title>Network intrusion detection system</title>
		<link>http://ksatriamatahari.wordpress.com/2008/06/30/network-intrusion-detection-system/</link>
		<comments>http://ksatriamatahari.wordpress.com/2008/06/30/network-intrusion-detection-system/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 20:34:57 +0000</pubDate>
		<dc:creator>ksatriamatahari</dc:creator>
				<category><![CDATA[computer science]]></category>

		<guid isPermaLink="false">http://ksatriamatahari.wordpress.com/?p=4</guid>
		<description><![CDATA[A network intrusion detection system (NIDS) is an intrusion detection system that tries to detect malicious activity such as denial of service attacks, port scans or even attempts to crack into computers by monitoring network traffic. The NIDS does this by reading all the incoming packets and trying to find suspicious patterns. If, for example, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=4&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A <strong>network intrusion detection system</strong> (<strong>NIDS</strong>) is an <a title="Intrusion detection system" href="http://en.wikipedia.org/wiki/Intrusion_detection_system">intrusion detection system</a> that tries to detect malicious activity such as <a class="mw-redirect" title="Denial of service" href="http://en.wikipedia.org/wiki/Denial_of_service">denial of service</a> attacks, <a class="mw-redirect" title="Port scan" href="http://en.wikipedia.org/wiki/Port_scan">port scans</a> or even attempts to <a title="Black hat" href="http://en.wikipedia.org/wiki/Black_hat">crack</a> into <a title="Computer" href="http://en.wikipedia.org/wiki/Computer">computers</a> by monitoring <a title="Computer network" href="http://en.wikipedia.org/wiki/Computer_network">network</a> traffic.</p>
<p>The NIDS does this by reading all the incoming <a title="Packet (information technology)" href="http://en.wikipedia.org/wiki/Packet_%28information_technology%29">packets</a> and trying to find suspicious patterns. If, for example, a large number of <a title="Transmission Control Protocol" href="http://en.wikipedia.org/wiki/Transmission_Control_Protocol">TCP</a> connection requests to a very large number of different <a title="TCP and UDP port" href="http://en.wikipedia.org/wiki/TCP_and_UDP_port">ports</a> are observed, one could assume that there is someone committing a <a title="Port scanner" href="http://en.wikipedia.org/wiki/Port_scanner">&#8220;port scan&#8221;</a> at some of the <a title="Computer" href="http://en.wikipedia.org/wiki/Computer">computer</a>(s) in the <a title="Computer network" href="http://en.wikipedia.org/wiki/Computer_network">network</a>. It also (mostly) tries to detect incoming <a title="Shellcode" href="http://en.wikipedia.org/wiki/Shellcode">shellcodes</a> in the same manner that an ordinary <a title="Intrusion detection system" href="http://en.wikipedia.org/wiki/Intrusion_detection_system">intrusion detection systems</a> does.</p>
<p>A NIDS is not limited to inspecting incoming <a title="Computer network" href="http://en.wikipedia.org/wiki/Computer_network">network</a> traffic only. Often valuable information about an ongoing intrusion can be learned from outgoing or local traffic as well. Some attacks might even be staged from the inside of the monitored <a title="Computer network" href="http://en.wikipedia.org/wiki/Computer_network">network</a> or <a title="Network segment" href="http://en.wikipedia.org/wiki/Network_segment">network segment</a>, and are therefore not regarded as incoming traffic at all.</p>
<p>Often, network intrusion detection systems work with other systems as well. They can for example update some <a class="mw-redirect" title="Firewall (networking)" href="http://en.wikipedia.org/wiki/Firewall_%28networking%29">firewalls</a>&#8216; <a title="Blacklist (computing)" href="http://en.wikipedia.org/wiki/Blacklist_%28computing%29">blacklist</a> with the <a title="IP address" href="http://en.wikipedia.org/wiki/IP_address">IP addresses</a> of <a title="Computer" href="http://en.wikipedia.org/wiki/Computer">computers</a> used by (suspected) <a title="Black hat" href="http://en.wikipedia.org/wiki/Black_hat">crackers</a>.</p>
<p>Certain <a class="mw-redirect" title="DISA" href="http://en.wikipedia.org/wiki/DISA">DISA</a> documentation, such as the Network <a title="Security Technical Implementation Guide" href="http://en.wikipedia.org/wiki/Security_Technical_Implementation_Guide">STIG</a>, uses the term NID to distinguish an internal <a title="Intrusion detection system" href="http://en.wikipedia.org/wiki/Intrusion_detection_system">IDS</a> instance from its outward-facing counterpart.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ksatriamatahari.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ksatriamatahari.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ksatriamatahari.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ksatriamatahari.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ksatriamatahari.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ksatriamatahari.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ksatriamatahari.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ksatriamatahari.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ksatriamatahari.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ksatriamatahari.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ksatriamatahari.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ksatriamatahari.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ksatriamatahari.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ksatriamatahari.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ksatriamatahari.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ksatriamatahari.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=4&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ksatriamatahari.wordpress.com/2008/06/30/network-intrusion-detection-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/20938f951cbc61a845d66b15e895fa30?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ksatriamatahari</media:title>
		</media:content>
	</item>
		<item>
		<title>Intrusion detection system</title>
		<link>http://ksatriamatahari.wordpress.com/2008/06/30/intrusion-detection-system/</link>
		<comments>http://ksatriamatahari.wordpress.com/2008/06/30/intrusion-detection-system/#comments</comments>
		<pubDate>Mon, 30 Jun 2008 20:33:58 +0000</pubDate>
		<dc:creator>ksatriamatahari</dc:creator>
				<category><![CDATA[computer science]]></category>

		<guid isPermaLink="false">http://ksatriamatahari.wordpress.com/?p=3</guid>
		<description><![CDATA[An intrusion detection system (IDS) generally detects unwanted manipulations of computer systems, mainly through the Internet. The manipulations may take the form of attacks by crackers. An IDS cannot detect attacks with encrypted traffic. An intrusion detection system is used to detect several types of malicious behaviors that can compromise the security and trust of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=3&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>An <strong>intrusion detection system</strong> (<strong>IDS</strong>) generally detects unwanted manipulations of <a title="Computer" href="http://en.wikipedia.org/wiki/Computer">computer systems</a>, mainly through the <a title="Internet" href="http://en.wikipedia.org/wiki/Internet">Internet</a>. The manipulations may take the form of attacks by <a class="mw-redirect" title="Cracker (computing)" href="http://en.wikipedia.org/wiki/Cracker_%28computing%29">crackers</a>. An IDS cannot detect attacks with encrypted traffic.</p>
<p>An intrusion detection system is used to detect several types of malicious behaviors that can compromise the security and trust of a computer system. This includes network attacks against vulnerable services, data driven attacks on applications, host based attacks such as privilege escalation, unauthorized logins and access to sensitive files, and <a title="Malware" href="http://en.wikipedia.org/wiki/Malware">malware</a> (<a title="Computer virus" href="http://en.wikipedia.org/wiki/Computer_virus">viruses</a>, <a title="Trojan horse (computing)" href="http://en.wikipedia.org/wiki/Trojan_horse_%28computing%29">trojan horses</a>, and <a title="Computer worm" href="http://en.wikipedia.org/wiki/Computer_worm">worms</a>).</p>
<p>An IDS is composed of several components: <strong>Sensors</strong> which generate security events, a <strong>Console</strong> to monitor events and alerts and control the sensors, and a central <strong>Engine</strong> that records events logged by the sensors in a database and uses a system of rules to generate alerts from security events received. There are several ways to categorize an IDS depending on the type and location of the sensors and the methodology used by the engine to generate alerts. In many simple IDS implementations all three components are combined in a single device or appliance.</p>
<h3><span class="mw-headline">Types of Intrusion-Detection systems</span></h3>
<p>In a network-based intrusion-detection system (NIDS), the sensors are located at choke points in the network to be monitored, often in the <a title="Demilitarized zone (computing)" href="http://en.wikipedia.org/wiki/Demilitarized_zone_%28computing%29">demilitarized zone</a> (DMZ) or at network borders. The sensor captures all network traffic and analyzes the content of individual packets for malicious traffic. In systems, PIDS and APIDS are used to monitor the transport and protocols illegal or inappropriate traffic or constructs of language (say SQL). In a host-based system, the sensor usually consists of a <a title="Software agent" href="http://en.wikipedia.org/wiki/Software_agent">software agent</a>, which monitors all activity of the host on which it is installed. Hybrids of these two systems also exist.</p>
<ul>
<li>A <a title="Network intrusion detection system" href="http://en.wikipedia.org/wiki/Network_intrusion_detection_system">network intrusion detection system</a> is an independent platform which identifies intrusions by examining network traffic and monitors multiple hosts. Network Intrusion Detection Systems gain access to network traffic by connecting to a <a class="mw-redirect" title="Network hub" href="http://en.wikipedia.org/wiki/Network_hub">hub</a>, <a title="Network switch" href="http://en.wikipedia.org/wiki/Network_switch">network switch</a> configured for <a title="Port mirroring" href="http://en.wikipedia.org/wiki/Port_mirroring">port mirroring</a>, or <a title="Network tap" href="http://en.wikipedia.org/wiki/Network_tap">network tap</a>. An example of a NIDS is <a title="Snort (software)" href="http://en.wikipedia.org/wiki/Snort_%28software%29">Snort</a>.</li>
</ul>
<ul>
<li>A <a title="Protocol-based intrusion detection system" href="http://en.wikipedia.org/wiki/Protocol-based_intrusion_detection_system">protocol-based intrusion detection system</a> consists of a system or agent that would typically sit at the front end of a server, monitoring and analyzing the communication protocol between a connected device (a user/PC or system). For a web server this would typically monitor the HTTPS protocol stream and understand the HTTP protocol relative to the web server/system it is trying to protect. Where HTTPS is in use then this system would need to reside in the &#8220;shim&#8221; or interface between where HTTPS is un-encrypted and immediately prior to it entering the Web presentation layer.</li>
</ul>
<ul>
<li>An <a title="Application protocol-based intrusion detection system" href="http://en.wikipedia.org/wiki/Application_protocol-based_intrusion_detection_system">application protocol-based intrusion detection system</a> consists of a system or agent that would typically sit within a group of servers, monitoring and analyzing the communication on application specific protocols. For example; in a web server with database this would monitor the SQL protocol specific to the middleware/business-login as it transacts with the database.</li>
</ul>
<ul>
<li>A <a title="Host-based intrusion detection system" href="http://en.wikipedia.org/wiki/Host-based_intrusion_detection_system">host-based intrusion detection system</a> consists of an agent on a host which identifies intrusions by analyzing system calls, application logs, file-system modifications (binaries, password files, capability/acl databases) and other host activities and state. An example of a HIDS is <a title="OSSEC" href="http://en.wikipedia.org/wiki/OSSEC">OSSEC</a>.</li>
</ul>
<ul>
<li>A <a class="new" title="Hybrid intrusion detection system (page does not exist)" href="http://en.wikipedia.org/w/index.php?title=Hybrid_intrusion_detection_system&amp;action=edit&amp;redlink=1">hybrid intrusion detection system</a> combines two or more approaches. Host agent data is combined with network information to form a comprehensive view of the network. An example of a Hybrid IDS is <a title="Prelude Hybrid IDS" href="http://en.wikipedia.org/wiki/Prelude_Hybrid_IDS">Prelude</a>.</li>
</ul>
<p><a id="Passive_system_vs._reactive_system" name="Passive_system_vs._reactive_system"></a></p>
<h2><span class="mw-headline">Passive system vs. reactive system</span></h2>
<p>In a <strong>passive system</strong>, the intrusion detection system (IDS) sensor detects a potential security breach, logs the information and signals an alert on the console and or owner. In a <strong>reactive system</strong>, also known as an <a class="mw-redirect" title="Intrusion prevention system" href="http://en.wikipedia.org/wiki/Intrusion_prevention_system">intrusion prevention system</a> (IPS), the IDS responds to the suspicious activity by resetting the connection or by reprogramming the firewall to block network traffic from the suspected malicious source. This can happen automatically or at the command of an operator.</p>
<p>Though they both relate to network security, an intrusion detection system (IDS) differs from a firewall in that a firewall looks outwardly for intrusions in order to stop them from happening. Firewalls limit access between networks to prevent intrusion and do not signal an attack from inside the network. An IDS evaluates a suspected intrusion once it has taken place and signals an alarm. An IDS also watches for attacks that originate from within a system.</p>
<p>This is traditionally achieved by examining network communications, identifying heuristics and patterns (often known as signatures) of common computer attacks, and taking action to alert operators. A system which terminates connections is called an <a class="mw-redirect" title="Intrusion prevention system" href="http://en.wikipedia.org/wiki/Intrusion_prevention_system">intrusion prevention system</a>, and is another form of an <a title="Application layer firewall" href="http://en.wikipedia.org/wiki/Application_layer_firewall">application layer firewall</a>.</p>
<p><a id="IDS_evasion_techniques" name="IDS_evasion_techniques"></a></p>
<h2><span class="mw-headline">IDS evasion techniques</span></h2>
<p><a title="Intrusion detection system evasion techniques" href="http://en.wikipedia.org/wiki/Intrusion_detection_system_evasion_techniques">Intrusion detection system evasion techniques</a> bypass detection by creating different states on the IDS and on the targeted computer. The adversary accomplishes this by manipulating either the attack itself or the network traffic that contains the attack.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ksatriamatahari.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ksatriamatahari.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ksatriamatahari.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ksatriamatahari.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ksatriamatahari.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ksatriamatahari.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ksatriamatahari.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ksatriamatahari.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ksatriamatahari.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ksatriamatahari.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ksatriamatahari.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ksatriamatahari.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ksatriamatahari.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ksatriamatahari.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ksatriamatahari.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ksatriamatahari.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=3&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ksatriamatahari.wordpress.com/2008/06/30/intrusion-detection-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/20938f951cbc61a845d66b15e895fa30?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ksatriamatahari</media:title>
		</media:content>
	</item>
		<item>
		<title>SUGENG RAWUH</title>
		<link>http://ksatriamatahari.wordpress.com/2008/06/23/halo-dunia/</link>
		<comments>http://ksatriamatahari.wordpress.com/2008/06/23/halo-dunia/#comments</comments>
		<pubDate>Mon, 23 Jun 2008 18:24:16 +0000</pubDate>
		<dc:creator>ksatriamatahari</dc:creator>
				<category><![CDATA[Tak Berkategori]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=1&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ksatriamatahari.wordpress.com&amp;blog=4052288&amp;post=1&amp;subd=ksatriamatahari&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ksatriamatahari.wordpress.com/2008/06/23/halo-dunia/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/20938f951cbc61a845d66b15e895fa30?s=96&#38;d=identicon" medium="image">
			<media:title type="html">ksatriamatahari</media:title>
		</media:content>
	</item>
	</channel>
</rss>
