Detecting Security Incidents

Incident Detection Phase

In order to be comletely reliable, a secure information system must have measures that allow it to detect incidents.

Thus, there are intrusion detection systems (or IDS) that monitor the network and are able to set off an alert when a request is suspicious or does not conform with the security policy.

Use of these probes and their parametering must be carefully studied because this type of mechanism is likely to generate a lot of false alarms.



Last update on Thursday October 16, 2008 02:43:15 PM


This document entitled « Detecting Security Incidents » from Kioskea (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.