Unit 3 of 4 · M.Sc IT Sem 4

Unit 3: Intrusion detection and firewalls

Information Security and Cyber Law notes · PTU syllabus (PGCA1932)

3 min read6 topics9 exam questions
On this page
  1. Unit summary
  2. Intruders
  3. Intrusion detection
  4. Firewalls
  5. Intrusion prevention systems
  6. Symmetric encryption principles
  7. Data Encryption Standard (DES)
  8. Key terms
  9. Quick revision
  10. Important questions

Unit summary

Intrusion detection and firewalls watch and filter traffic, while encryption protects data itself. This unit covers intruders, host- and network-based intrusion detection, honeypots, firewall types and basing, intrusion prevention systems, symmetric encryption principles and DES.

After this unit you can

  • Explain intruders and intrusion detection approaches
  • Compare host-based and network-based IDS; describe honeypots
  • Explain firewall characteristics, types and basing
  • Explain symmetric encryption and DES

PTU syllabus topics

  • Intruders and intrusion detection
  • host-based and network-based intrusion detection
  • honeypots
  • firewall need/characteristics/types/basing
  • intrusion prevention systems
  • symmetric encryption principles
  • Data Encryption Standard
ComparisonTypes of firewall
Checks
Strength

Packet filter

IP, port, protocol per packet

Fast, simple

Stateful inspection

Connection state

Smarter than packet filters

Application proxy

Full application content

Deep inspection, slower

Next-generation

Apps, users, threats

Integrated IPS and more

1

Topic 1

Intruders

Key termsClasses of intruders
Masquerader
Outsider using a legitimate user's account
Misfeasor
Insider who misuses access or accesses data not authorised
Clandestine user
Seizes supervisory control to evade auditing
  • Intrusion techniques: password guessing and cracking, phishing, exploiting unpatched software, sniffing, privilege escalation. Defences: strong password policies, salted password hashing, account lockout, MFA, monitoring.
2

Topic 2

Intrusion detection

ComparisonIDS types
Host-based (HIDS)
Network-based (NIDS)

Monitors

Logs, files and system calls on one host

Packets on a network segment

Sees

Encrypted traffic after decryption; insider actions

Network-wide attacks, scans

Example

OSSEC, Wazuh, Tripwire

Snort, Suricata, Zeek

ComparisonDetection methods
Signature (misuse)
Anomaly

Approach

Matches known attack patterns

Flags deviation from normal behaviour

Strength

Few false positives

Can catch new (zero-day) attacks

Weakness

Misses new attacks

More false positives

  • Honeypot: a decoy system with no production value that lures attackers, diverting them and recording their methods; a honeynet is a network of honeypots.
3

Topic 3

Firewalls

Key termsFirewall characteristics
Choke point
All traffic passes through it
Policy enforcement
Only authorised traffic allowed
Immune
Itself hardened against attack
ComparisonFirewall types
Works at
Notes

Packet filter

Network layer — IP, port, protocol

Fast, stateless

Stateful inspection

Tracks connection state

Allows replies to established sessions

Application-level gateway (proxy)

Application layer

Inspects content; slower

Circuit-level gateway

Session layer

Relays TCP connections (SOCKS)

Next-generation firewall

All layers with app awareness and IPS

Palo Alto, Fortinet

Key termsFirewall basing
Bastion host
Hardened system running proxies
Host-based firewall
Software on each machine (Windows Defender Firewall, iptables)
Personal firewall
For home PCs
DMZ
Network zone between external and internal firewalls for public servers
Distributed firewalls
Centrally managed host firewalls
4

Topic 4

Intrusion prevention systems

  • Personal firewall: software on an individual device (Windows Defender Firewall) controlling its incoming and outgoing connections — important for remote workers.
  • Intrusion detection system (IDS): monitors traffic or hosts for suspicious activity and alerts administrators; intrusion prevention system (IPS) also blocks it.
ComparisonIDS approaches
Signature-based
Anomaly-based

Method

Matches known attack patterns

Flags deviations from normal behaviour

Strength

Accurate for known attacks

Can detect new attacks

Weakness

Misses new attacks

More false alarms

  • Types: network-based (NIDS) and host-based (HIDS); modern security operations centres use SIEM tools to correlate alerts.
  • IDS response: passive (alert, log) or active (block IP, reset connection — IPS). Honeypots lure attackers to study their methods.
5

Topic 5

Symmetric encryption principles

ProcessSymmetric encryption model
  1. 1Plaintext
  2. 2Encryption algorithm with the secret key
  3. 3Ciphertext sent over the channel
  4. 4Decryption algorithm with the same key
  5. 5Plaintext recovered
Key termsRequirements
Strong algorithm
Secure even if the algorithm is known (Kerckhoffs)
Secret key
Shared securely and kept secret
Block vs stream cipher
Blocks of bits vs bit-by-bit (AES vs ChaCha20)
Confusion and diffusion
Hide key-ciphertext relation; spread plaintext influence
6

Topic 6

Data Encryption Standard (DES)

  • Data Encryption Standard (DES, 1977): a symmetric block cipher based on the Feistel structure; 64-bit block, 56-bit effective key (64 with parity), 16 rounds, 48-bit round keys.
ProcessDES structure
  1. 1Initial permutation of the 64-bit block
  2. 2Split into left and right 32-bit halves
  3. 316 Feistel rounds

    Right half expanded to 48 bits, XORed with round key, passed through 8 S-boxes, permuted, XORed with left half; halves swapped

  4. 432-bit swap
  5. 5Final permutation (inverse of the initial) gives the ciphertext
  • Analysis: the 56-bit key is too short — brute-forced in 1998 (EFF's DES Cracker) in days; avalanche effect is strong; S-boxes resist differential cryptanalysis. Triple DES (encrypt–decrypt–encrypt with two or three keys) extended its life but is now deprecated.

Key terms

HIDS
Host-based intrusion detection system
Anomaly detection
Detecting deviations from normal behaviour
Honeypot
Decoy system to lure attackers
DMZ
Network segment for public-facing servers
Feistel structure
Round structure used by DES

Quick revision

  • Masquerader, misfeasor, clandestine user.
  • HIDS vs NIDS; signature vs anomaly; honeypots.
  • Firewall characteristics, types, basing, DMZ; IPS.
  • Symmetric model; DES 64-bit block, 56-bit key, 16 rounds; 3DES.

Important exam questions

Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).

Short-answer questions

  1. Q1.What is a misfeasor?
  2. Q2.Distinguish HIDS and NIDS.
  3. Q3.What is a honeypot?
  4. Q4.Name three firewall types.
  5. Q5.What is a DMZ?
  6. Q6.What is the key length of DES?

Long-answer questions

  1. Q1.Explain intrusion detection systems and honeypots.
  2. Q2.Explain the types and basing of firewalls.
  3. Q3.Explain the structure of DES.

Stuck on this unit?

Message SBS on WhatsApp for help with Information Security and Cyber Law, or to ask about studying M.Sc IT at Synetic.

WhatsApp us