Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

1.Is a firewall sufficient in blocking outside intrusion? Why or Why Not? 2.Defi

ID: 3719473 • Letter: 1

Question

1.Is a firewall sufficient in blocking outside intrusion? Why or Why Not?

2.Define NIDS and HIDS. What are their pros and cons of NIDS and HIDS?

3.What are the differences between misuse detection model and anomaly detection model? What is false positive?

4.What is DMZ? How does the DMZ enhance security?

5.Describe how digital certificate are used during the handshake process of SSL.

6.How can you determine whether an email is forged or not? List the tools you may need to use.

7.What is spam? What kind of damage can a spam cause? How to control spam email?

8.Describe how cross-site scripting (XSS) works. What kind of damage it may cause to the victim computer?

9.How to authenticate a web server?

10.Describe how SQL injection works. What are the major preventive measures against it?

Explanation / Answer

[1]
Firewall is used to prevent unauthorised access to or from a private computer network but not sufficient for security purpose. One of the most common risk with is malware [acquired through clicking on email attachments and email links], SPAM are not covered by firewall.

[2]
NIDS : Network intrusion detection system is a security tool that between to the side of the network. NIDS handle monitors traffic. NIDA having management console and sensors which use to detect the activities.

HIDS : Host Intrusion Detection Systems is an HOST based systems which is used to monitors, comparing new entries to attack signatures.

[3]

Anomaly-based detection is an two-step process which is training a system with data to establish some notion of normality and then use the established profile on real data to flag deviations.
Misuse detection is an abnormal system behaviour is defined first, and then all other behaviour is defined as normal.

[4]

DMZ : De-Militarized Zoneis a special local network configuration designed to improve security by segregating computers on each side of a firewall.