Detecting Network Attacks · 检测网络攻击
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| NIDS/nɪdz/ | 网络入侵检测系统 | wǎng luò rù qīn jiǎn cè xì tǒng |
| NIPS/nɪps/ | 网络入侵防御系统 | wǎng luò rù qīn fáng yù xì tǒng |
| SIEM/siːm/ | 安全信息与事件管理 | ān quán xìn xī yǔ shì jiàn guǎn lǐ |
| signature-based/ˈsɪɡnɪtʃə beɪst/ | 基于特征 | jī yú tè zhēng |
| anomaly-based/əˈnɒməli beɪst/ | 基于异常 | jī yú yì cháng |
| baseline/ˈbeɪslaɪn/ | 基线 | jī xiàn |
Detection systems
- A NIDS 网络入侵检测系统 analyses traffic and raises an alert, but does not block.
- A NIPS 网络入侵防御系统 can also stop an attack.
- A SIEM 安全信息与事件管理 gathers data from many sources to spot patterns.
检测系统
- NIDS(网络入侵检测系统)分析流量并发出警报,但不阻止。
- NIPS(网络入侵防御系统)还能阻止攻击。
- SIEM(安全信息与事件管理)从许多来源收集数据以发现模式。
Two detection methods
- Signature-based 基于特征: matches known attack signatures — fast, few false alarms.
- Anomaly-based 基于异常: compares to a normal baseline 基线 — catches new attacks.
- A hybrid approach combines both.
两种检测方法
- 基于特征(signature-based):匹配已知攻击特征——快,误报少。
- 基于异常(anomaly-based):与正常基线(baseline)比较——能发现新攻击。
- 混合方法结合两者。
Signature-based or anomaly-based detection? · 基于特征或基于异常的检测?
Signature-based matches known attacks (fast, few false alarms); anomaly-based flags deviations from normal (catches new attacks). · 基于特征匹配已知攻击(速度快,误报少);基于异常标记偏离正常的行为(可捕获新攻击)。
Which system detects an attack and raises an alert but does NOT block it? · 哪个系统检测到攻击并发出警报但不拦截它?
A NIDS alerts only; a NIPS can block. · NIDS 仅发出警报;NIPS 可以拦截。
Which detection method is more likely to catch a brand-new attack? · 哪种检测方法更有可能捕获全新攻击?
Anomaly-based flags the unusual; signatures miss the new. · 基于异常 标记异常行为;特征无法识别新攻击。
Anomaly-based detection compares traffic to a normal ____. · 基于异常检测将流量与正常____进行比较。
It flags deviation from the baseline · 基线. · 它标记偏离基线的行为。
Which describe a SIEM? (Choose all) · 以下哪项描述SIEM?(多选)
A SIEM is software, not a physical lock. · SIEM是软件,不是物理锁。
The trade-off
- Signature-based is blind to brand-new attacks (more false negatives).
- Anomaly-based costs more and raises more false alarms.
- Choose by traffic volume, novelty risk, and budget.
权衡
- 基于特征对全新攻击视而不见(更多漏报)。
- 基于异常成本更高且引发更多误报。
- 按流量大小、新颖性风险和预算来选择。
Do not confuse an IDS with an IPS. An intrusion detection system only alerts — a human must act. An intrusion prevention system can block the attack itself. The one letter changes what happens.
不要混淆IDS和IPS。入侵检测系统只警报——需要人来行动。入侵防御系统能自己阻止攻击。一个字母改变了会发生什么。
Signature-based detection is fast and has few false positives. · 基于特征检测速度快且误报少。
But it misses attacks with no known signature. · 但它会遗漏没有已知特征的攻击。
A new, never-seen worm hits the network. A signature-based system has no signature for it, so it misses it (a false negative). An anomaly-based system notices the unusual traffic pattern and flags it — the classic reason to include anomaly detection.
一种从未见过的新蠕虫袭击网络。基于特征的系统没有它的特征,所以漏掉了它(漏报)。基于异常的系统注意到异常的流量模式并标记它——这正是纳入异常检测的经典理由。
Detect network attacks with a NIDS (alerts), NIPS (blocks), or SIEM (correlates). Signature-based detection is fast but misses new attacks; anomaly-based catches novel attacks but costs more and raises false alarms. Pick by volume, novelty, and budget.
用NIDS(警报)、NIPS(阻止)或SIEM(关联)检测网络攻击。基于特征的检测快但漏掉新攻击;基于异常的能发现新攻击但成本更高且误报更多。按流量、新颖性和预算选择。