Network Intrusions

Network intrusions are a serious threat to Florida businesses. They can easily cripple a small, unprepared business.

Take Note:
An intrusion may have already happened without you noticing because your system seems to be operating normally.

Hackers can breach your network's defenses from remote locations, or try to physically break into your organization to access your valuable information. Intruders seek unpatched software vulnerabilities and develop sophisticated programs to rapidly penetrate those systems. An intrusion can be achieved in seconds.

Even if your organization has a comprehensive information security protection system, it is essential that you closely monitor your information assets for signs of intrusion.

To prevent intrusions, you need to develop a strategy for handling intrusions that includes preparation, detection, and response.

Intrusion Detection Systems (IDS)

These preventative security management systems analyze information from various areas within a computer or a network, and identify potential security breaches including both internal and external threats.

IDS functions include:

  • Monitoring and analyzing both internal and external activities.
  • Analyzing system configurations.
  • Looking for vulnerabilities.
  • Assessing system and file integrity.
  • Recognizing patterns typical of attacks.
  • Analyzing and notifying when abnormal activity patterns occur.
  • Auditing violations of user policy.

IDS is being developed in response to the increasing number of attacks on major sites and networks. Unfortunately, potential methods of attack are becoming more sophisticated and less technical ability is required for the novice attacker.

An IDS follows a two-step process:

  1. Passive Component — Inspection of the system's configuration files to detect vulnerabilities within the settings; inspection of the password files to detect inefficient passwords; and inspection of user activities to detect policy violations.
  2. Active Component — Attacks to a network are replicated, and the system's response to these attacks is recorded. This method is used to detect weaknesses within the system.

For more information about network security and intrusion detection, visit WindowSecurity.com's Intrusion Detection page.