Unit 3: Intrusion detection and firewalls
Information Security and Cyber Law notes · PTU syllabus (PGCA1932)
On this page
Unit summary
Intrusion detection and firewalls watch and filter traffic, while encryption protects data itself. This unit covers intruders, host- and network-based intrusion detection, honeypots, firewall types and basing, intrusion prevention systems, symmetric encryption principles and DES.
After this unit you can
- Explain intruders and intrusion detection approaches
- Compare host-based and network-based IDS; describe honeypots
- Explain firewall characteristics, types and basing
- Explain symmetric encryption and DES
PTU syllabus topics
- Intruders and intrusion detection
- host-based and network-based intrusion detection
- honeypots
- firewall need/characteristics/types/basing
- intrusion prevention systems
- symmetric encryption principles
- Data Encryption Standard
Packet filter
IP, port, protocol per packet
Fast, simple
Stateful inspection
Connection state
Smarter than packet filters
Application proxy
Full application content
Deep inspection, slower
Next-generation
Apps, users, threats
Integrated IPS and more
Topic 1
Intruders
- Masquerader
- Outsider using a legitimate user's account
- Misfeasor
- Insider who misuses access or accesses data not authorised
- Clandestine user
- Seizes supervisory control to evade auditing
- Intrusion techniques: password guessing and cracking, phishing, exploiting unpatched software, sniffing, privilege escalation. Defences: strong password policies, salted password hashing, account lockout, MFA, monitoring.
Topic 2
Intrusion detection
Monitors
Logs, files and system calls on one host
Packets on a network segment
Sees
Encrypted traffic after decryption; insider actions
Network-wide attacks, scans
Example
OSSEC, Wazuh, Tripwire
Snort, Suricata, Zeek
Approach
Matches known attack patterns
Flags deviation from normal behaviour
Strength
Few false positives
Can catch new (zero-day) attacks
Weakness
Misses new attacks
More false positives
- Honeypot: a decoy system with no production value that lures attackers, diverting them and recording their methods; a honeynet is a network of honeypots.
Topic 3
Firewalls
- Choke point
- All traffic passes through it
- Policy enforcement
- Only authorised traffic allowed
- Immune
- Itself hardened against attack
Packet filter
Network layer — IP, port, protocol
Fast, stateless
Stateful inspection
Tracks connection state
Allows replies to established sessions
Application-level gateway (proxy)
Application layer
Inspects content; slower
Circuit-level gateway
Session layer
Relays TCP connections (SOCKS)
Next-generation firewall
All layers with app awareness and IPS
Palo Alto, Fortinet
- Bastion host
- Hardened system running proxies
- Host-based firewall
- Software on each machine (Windows Defender Firewall, iptables)
- Personal firewall
- For home PCs
- DMZ
- Network zone between external and internal firewalls for public servers
- Distributed firewalls
- Centrally managed host firewalls
Topic 4
Intrusion prevention systems
- Personal firewall: software on an individual device (Windows Defender Firewall) controlling its incoming and outgoing connections — important for remote workers.
- Intrusion detection system (IDS): monitors traffic or hosts for suspicious activity and alerts administrators; intrusion prevention system (IPS) also blocks it.
Method
Matches known attack patterns
Flags deviations from normal behaviour
Strength
Accurate for known attacks
Can detect new attacks
Weakness
Misses new attacks
More false alarms
- Types: network-based (NIDS) and host-based (HIDS); modern security operations centres use SIEM tools to correlate alerts.
- IDS response: passive (alert, log) or active (block IP, reset connection — IPS). Honeypots lure attackers to study their methods.
Topic 5
Symmetric encryption principles
- 1Plaintext
- 2Encryption algorithm with the secret key
- 3Ciphertext sent over the channel
- 4Decryption algorithm with the same key
- 5Plaintext recovered
- Strong algorithm
- Secure even if the algorithm is known (Kerckhoffs)
- Secret key
- Shared securely and kept secret
- Block vs stream cipher
- Blocks of bits vs bit-by-bit (AES vs ChaCha20)
- Confusion and diffusion
- Hide key-ciphertext relation; spread plaintext influence
Topic 6
Data Encryption Standard (DES)
- Data Encryption Standard (DES, 1977): a symmetric block cipher based on the Feistel structure; 64-bit block, 56-bit effective key (64 with parity), 16 rounds, 48-bit round keys.
- 1Initial permutation of the 64-bit block
- 2Split into left and right 32-bit halves
- 316 Feistel rounds
Right half expanded to 48 bits, XORed with round key, passed through 8 S-boxes, permuted, XORed with left half; halves swapped
- 432-bit swap
- 5Final permutation (inverse of the initial) gives the ciphertext
- Analysis: the 56-bit key is too short — brute-forced in 1998 (EFF's DES Cracker) in days; avalanche effect is strong; S-boxes resist differential cryptanalysis. Triple DES (encrypt–decrypt–encrypt with two or three keys) extended its life but is now deprecated.
Key terms
- HIDS
- Host-based intrusion detection system
- Anomaly detection
- Detecting deviations from normal behaviour
- Honeypot
- Decoy system to lure attackers
- DMZ
- Network segment for public-facing servers
- Feistel structure
- Round structure used by DES
Quick revision
- Masquerader, misfeasor, clandestine user.
- HIDS vs NIDS; signature vs anomaly; honeypots.
- Firewall characteristics, types, basing, DMZ; IPS.
- Symmetric model; DES 64-bit block, 56-bit key, 16 rounds; 3DES.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.What is a misfeasor?
- Q2.Distinguish HIDS and NIDS.
- Q3.What is a honeypot?
- Q4.Name three firewall types.
- Q5.What is a DMZ?
- Q6.What is the key length of DES?
Long-answer questions
- Q1.Explain intrusion detection systems and honeypots.
- Q2.Explain the types and basing of firewalls.
- Q3.Explain the structure of DES.
Stuck on this unit?
Message SBS on WhatsApp for help with Information Security and Cyber Law, or to ask about studying M.Sc IT at Synetic.
