Introduction to Packet Capture and Intrusion Detection/Prevention Systems

profilemzsweetee13
cstp2_Stepsforcompletion..docx

The following is a suggested outline for the paper:

1. Introduction: Describe the banking institution and the issue you will be examining.

2. Overview of the Network Architecture

3. Network Attacks

4. Network Traffic Analysis and Results

5. Other Detection Tools and Techniques

6. Recommended Remediation Strategies

Step 1: Create a Network Architecture Overview

Provide a network architecture overview along with diagrams. Your overview can be fictitious or based on an actual organization. The goal is to provide an understanding of the network architecture.

Describe the various data transmission components: User Datagram Protocol (UDP), Transmission Control Protocol/Internet Protocol (TCP/IP), internet packets, IP address schemes, well-known ports and application.

Address the meaning and relevance of information, such as:

1. the sender or source that transmits a message

2. the encoder used to code messages

3. the medium or channel that carries the message

4. the decoding mechanisms used

5. the receiver or destination of the messages

Describe:

the intrusion detection system (IDS), the intrusion prevention system (IPS), the firewalls that have been established,

the link between the operating systems, the software, and hardware components in the network, firewall, and IDS that make up the network defense implementation of the banks’ networks.

Identify:

1. how banks use firewalls

2. how banks use IDSs

3. the difference between these technologies

Include:

1. the network infrastructure information

2. the IP address schemes that will involve the IP addressing assignment model

3. the public and private addressing and address allocations

4. potential risks in setting up the IP addressing scheme

Identify:

1. any well-known ports and applications that are used

2. risks associated with those ports and applications being identified and possibly targeted

Add your overview to your report.

Step 2: Identify Network Attacks

identify possible cyberattacks such as spoofing/cache poisoning, session hijacking, and man-in-the-middle attacks.

Propose a honeypot environment to lure hackers to the network and include the following in your proposal:

1. Describe a honeypot.

2. Explain how a honeypot environment is set up.

3. Explain the security and protection mechanisms a bank would need for a honeypot.

4. Discuss some network traffic indicators that will tell you that your honeypot trap is working.

Step 3: Identify False Positives and False Negatives

1. Identify what are false positives and false negatives.

2. How are false positives and false negatives determined?

3. How are false positives and false negatives tested?

4. Which is riskier to the health of the network, a false positive or a false negative?

Describe your analysis about testing for false negatives and false positives using tools such as IDSs and firewalls, and include this as recommendations for the banks in your public service Joint Network Defense Bulletin.

Discuss the concept of performing statistical analysis of false positives and false negatives.

Explain how banks can reduce these issues.

Step 4: Determine Sensitivity of Your Analysis

Information appropriate for internal consumption may not be appropriate for public consumption.

Once you have assessed the sensitivity of the information, include appropriate information in your Malicious Network Activity Report.

Then, include appropriate information in the Joint Network Defense Bulletin (for the Public) in a way that educates the financial services consortium of the threat and the mitigating activities necessary to protect against that threat.

Step 5: Explain Other Detection Tools and Techniques

In the previous step, you included appropriate information in the proper document. In this step, perform independent research and briefly discuss what other tools and techniques may be used to detect these signatures.

Provide enough detail so that a bank network administrator could follow your explanation to deploy your system in production. Include this information in the Joint Network Defense Bulletin.