MIS 464 Final Exam Review - Questions and Answers Alarm Clustering and Compaction This is the process of grouping almost identical alarms that occur nearly at the same time into a single higher level alarm Alert or Alar
...
MIS 464 Final Exam Review - Questions and Answers Alarm Clustering and Compaction This is the process of grouping almost identical alarms that occur nearly at the same time into a single higher level alarm Alert or Alarm An indication that a system has just been attacked Alarm Filtering the process of classifying alerts so they can be more effectively managed False negative Failure of an IDPS to react to an actual attack event False Attack Stimulus An event that triggers an alarm when no actual attack is in progress The process by which the attacker changes the format and/or timing of their activities to avoid being detected False The process of entrapment is when an attacker changes the format and/or timing of their activities to avoid being detected by an IDPS. Noise Alarm events that are accurate and noteworthy but do not pose significant threats to information security False Positive An alert or alarm that occurs in the absence of an actual attack Site Policy The rules and configuration guidelines governing the implementation and operation of an IDPS within the organization Site Policy Awareness An IDS's ability to dynamically modify its site policies in reaction or response to environmental activity. Tuning The process of adjusting an IDPS to maximize its efficiency in detecting true positives while minimizing false positives and false negatives True Attack Stimulus An event that triggers an alarm and causes an IDPS to react as if a real attack is in progress IDPS Signature-Based Detection • Examines network traffic in search of patterns that match known signatures • Widely used because many attacks have clear and distinct signatures IDPS Behavior-based Detection • Anomaly-based detection (or behavior-based detection) collects statistical summaries by observing traffic known to be normal. • When measured activity is outside baseline parameters or clipping level, IDPS sends alert to administrator. • IDPS can detect new types of attacks. Honeypots • Divert attacker from accessing critical systems • Collect information about attacker's activity • Encourage attacker to stay on a system long enough for administrators to document the event and perhaps respond
[Show More]