Learn what intrusion detection and prevention systems are. Jungwoo describes their roles in network security and how intrusion detection systems are different from intrusion prevention systems. He also talks about the two primary mechanisms behind intrusion detection and prevention systems: signature and behavior-based approaches.
- [Instructor] The best defense in network security…is to constantly monitor for suspicious activities…to either prevent attacks or stop them…before they incur significant damage.…When a system passively observes network traffic…to recognize a security threat…it is labeled as an intrusion detection system, or IDS.…If the same system has an additional ability…to drop network traffic based on it's observation…it is called an intrusion prevention system, or IPS.…
You can configure a system to either act…as an IDS or IPS according to your needs.…Many traditional IDS's rely…on signature-based detection approach.…They look for a static pattern in network traffic…and find a match from a database…of known malicious signatures.…Since certain network attacks always begin…with sending a certain big pattern,…signature-based IDS's are looking for a string…consisting of binary numbers…constituting the network attack traffic.…
One of the major weaknesses in this method…is that unknown patterns cannot be detected…so any novel attacks can get through.…
- Identify the goals of network security.
- Distinguish types of firewalls.
- Explain intrusion detection and prevention systems.
- Describe packet capture.
- Collect packet sniffer, IDS, and IPS data.
- Explain how to use machine learning to process network data.
- Use data science to conduct a network forensics investigation.
- Identify data visualization targets and tools.
Skill Level Intermediate
1. Network Security Review
2. Network Data Sources
3. Data Collection
4. Data Analytics
Network forensics2m 25s
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.Cancel
Take notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.