November 2012
Intermediate to advanced
1200 pages
78h 13m
English
Almantas Kakareka, CISSP, GSNA, GSEC, CEH, Demyo, Inc.
First things first: Detecting system intrusion is not the same as Intrusion Detection System/Intrusion Prevention System (IDS/IPS). We want to detect system intrusion once attackers pass all defensive technologies in the company (such as IDS/IPS mentioned above), full-packet capture devices with analysts behind them, firewalls, physical security guards, and all other preventive technologies and techniques. Many preventative technologies are using blacklisting [1] most of the time, and thus that’s why they fail. Blacklisting is allowing everything by default and forbidding something that is considered to be malicious. So, for the attacker, ...
Read now
Unlock full access