Add the rest of university notes

This commit is contained in:
John Gatward committed 2026-10-04 14:02:35 +01:00
1 parent c1b84c7f7d
commit d0f27f276b
366 files changed
+9844 -110

No files matched your search

@@ -0,0 +1,137 @@
### Anti-Virus
- Signature-based detection
- Store some small code signature for each virus
- Scan files either in bulk or at run-time, compare with the signatures on file
- Generic signatures
- Hashing the entire file is a bad idea, the author only needs to add a `nop` to completely change the signature
- Also hashing every executable is slow
- Instead we identify key pieces of the malware and hash that
- ![1648478154.png](img/1648478154.png)
- This method is never going to catch a virus it’s never seen before
- Heuristics
- Determine what actions and rules a virus program will normally adopt
- Start the program in a `VM` and see what it does
- Theoretically could detect a virus that doesn’t strictly match some signature
- Only if it does the same thing as a virus its seen before
- A lot slower than signature detection as it needs to be run in a VM before the user is allowed to open it
- What if the virus sleeps for 20 seconds before doing anything? very hard to detect
- Machine learning
- ![1648478649.png](img/1648478649.png)
### Network Attack Models
- Firewalls don’t protect against
- Attacks using valid protocols
- Insider attacks
Intrusion **Detection** Systems (IDS)
- Detects possible intrusion attempts
- Generates alerts and logs for administrators
Intrusion **Prevention** Systems (IPS)
- Identical to IDS except also stops the attack
#### IDS Deployment
- Host-based (HIDS)
- Monitors a *single host* to find suspicious activity including resource / app usage
- In many ways modern anti-virus does this
- Additional layer of security software running on a host within a protected LAN or VPN
- Creates a profile of usage for specific users
- Can monitor CPU, memory use, application use and the network stack
- Network-based (NIDS)
- Monitors **network traffic** and analyses packets from different protocols to identify suspicious activity
- Placed at a viewpoint on a network to examine and analyse traffic
- Installed on a firewall or in a DMZ
- Installed behind a screened subnet
- May perform deeper analysis than many firewalls
- like stateful protocol analysis and deep packet inspection
##### Components of a IDS
- Sensors / Agents: collect and collate data from multiple viewpoints on a network
- Analysers: ascertain if an intrusion has taken place
- Reporting: notify the administrators via alerts on a console or graphical interface
> Multiple sensors allow us to **distribute capture**, but **centralise** computing **overhead**
##### Detection Modes
- **Stateful Protocol analysis**
- More complex version of a stateful packet filter
- Hold detailed session information on protocols being used, examine for attacks
- Why is this user logging on as root?
- Why is this command being send a 1000 byte buffer as a parameter (buffer overflow)
- Computationally costly and requires the IDS have all possible versions of these protocols defined in its database
- **Signature-based**
- Fingerprinting sequences of operations or packets
- Like antivirus, signatures are created and stored in a database - operations as well as binaries
- If operations match a defined singature, then an alarm is triggered
- Include some form of attack language
- Mechanisms to describe sequences of events
- Maintain and monitor intermediate states and event transitions
- The pros and cons of these systems are identical to their anti-virus counterpart
- Computationally efficient
- Always spots know attacks
- Always misses unknown attacks
- Detailed signature databases must be kept up-to-date
- Example: If there is a large amount of `ICMP` traffic, many `TCP` packets (`SYN` packets)
- These connections going to a variety of other hosts
- *If a host establishes more than 3 tcp connections to different hosts in 5 seconds, its port scanning*
- **Anomaly-based**
- Built a model of *normal* and find deviations
- Anomaly detection has wide-ranging application from IDS to banking fraud
- Build up a picture of normal usage, and detect when usage moves beyond what is normal
- Always a trade off between **false positives** and **false negatives**
- ![1648481248.png](img/1648481248.png)
- Run a host within a quarantined environment and collect training data
- Constructed by monitoring audit logs
- Sometimes rely on analysis of sequences of system calls through normal behaviour
- ![1648481362.png](img/1648481362.png)
- However network traffic is more complex than a normal curve
- ![1648481744.png](img/1648481744.png)
- Very hard to decide if network traffic is nefarious or not
###### Snort
- Snort is a powerful and well established IDS
- Also free!
- Uses rules to analyse network packets, and then can provide alerts or logging
- Snort has built in rules for detecting `nmap`m a logged scan may look like this:
- ![1648480866.png](img/1648480866.png)
- The machine `10.0.4.1` is sending out packets with incremented port numbers
- The time stamps on the data show the packets are being sent extremely quickly
- All these packets are synchronised packets, its not waiting for `ACK` packets
###### Nmap Timings
- You can avoid detection when using `nmap` by reducing the speed of the scan
- The makes port scanning very hard to distinguish from general network noise
- `nmap` contains 6 timing options
- paranoid mode leaves 5 minutes between packets
- insane mode is basically a DDOS attack
#### Machine Learning
- Machine learning approaches train a model to make predictions on data
- Support vector machines, neural networks etc
##### Neural Networks for ID
- A network can be pre-trained
- Sensor measurements are then passed through the network
- Activations in the specific output neuron signal an alert
![1648481908.png](img/1648481908.png)
- Scales badly
- Search space can increase exponentially
- Real-time data
- False negatives
- Limits in the representation
- What is normal can change
- Do we retrain and risk learning an intruders behaviour?