Computer Security and Cyber LawUnit 812 min read
Intrusion Detection & Response: Systems, Models & Threat Handling
Unit 8 of Computer Security and Cyber Law covers Intrusion Detection Systems (IDS), their architectures (network/host-based), detection techniques (signature/anomaly/behavioral), response mechanisms (prevention/mitigation), and real-world incident response workflows—with case studies from Nepali cybersecurity incidents
TAKEAWAYS:
- IDS vs. IPS: An Intrusion Detection System (IDS) monitors and alerts, while an Intrusion Prevention System (IPS) blocks threats in real-time (like a security guard vs. a bouncer).
- Detection Techniques: Signature-based (like antivirus) detects known attacks; anomaly-based flags unusual behavior (e.g., sudden spikes in login attempts to eSewa).
- Response Lifecycle: Detect → Analyze → Contain → Eradicate → Recover → Lessons Learned (mirrors how NTC isolates a DDoS attack).
- False Positives/Negatives: A false positive (e.g., flagging a Daraz customer’s bulk order as a bot attack) wastes resources; a false negative (missing a Pathao driver’s GPS spoofing) risks breaches.
- Honeypots: Decoy systems (like fake NEPSE trading accounts) lure attackers to study their tactics without harming real assets.
- Legal Compliance: In Nepal, Electronic Transactions Act 2008 mandates logging and reporting intrusions to the National Cyber Security Center (NCSC).
1. What is an Intrusion Detection System (IDS)?
An IDS is a security tool that monitors network traffic or system activities for malicious or policy-violating actions (e.g., unauthorized access, malware, DDoS). It does not block threats—that’s the job of an IPS—but alerts administrators so they can respond.
How IDS Works: The Core Process
flowchart TD
A["**Data Source**\n(Network traffic, logs, system calls)"] --> B["**Sensor/Collector**\n(Captures data in real-time)"]
B --> C["**Analysis Engine**\n(Compares against rules/baselines)"]
C -->|"Match Found"| D["**Alert Generation**\n(Sends notification to admin)"]
C -->|"No Match"| E["**Normal Operation**\n(Continues monitoring)"]
D --> F["**Response Action**\n(Manual or automated)"]2. Types of IDS: Where and How They Monitor
IDS can be classified based on where they operate and how they detect threats.
A. By Deployment Location
| Type | Where It Monitors | Example Use Case | Real-World Analog |
|---|---|---|---|
| Network-Based IDS (NIDS) | Network traffic (e.g., router, switch) | Detecting a DDoS attack on Ncell’s 4G network | Like a firewall but only alerts, not blocks. |
| Host-Based IDS (HIDS) | Single device (e.g., server, PC) | Flagging unauthorized file changes on a bank’s database server | Like an antivirus scanning your laptop. |
| Hybrid IDS | Combines NIDS + HIDS | Protecting eSewa’s payment gateway | Uses both network and host sensors. |
B. By Detection Technique
| Technique | How It Works | Pros | Cons | Example |
|---|---|---|---|---|
| Signature-Based | Matches known attack patterns (like antivirus) | Fast, low false positives | Only detects known threats | Detecting SQL injection in Daraz’s checkout. |
| Anomaly-Based | Flags deviations from normal behavior | Detects zero-day attacks | High false positives | Sudden login attempts from India to your Khalti account. |
| Behavioral-Based | Learns "normal" user/process behavior | Adapts to new threats | Complex to configure | A Pathao driver’s app acting like a bot. |
3. Key Components of an IDS
Every IDS has 4 core components, visualized below:
classDiagram
class Sensor {
+Collects data from network/host
+Uses sniffers (e.g., Wireshark) or logs
}
class AnalysisEngine {
+Compares data against rules/baselines
+Uses ML for anomaly detection
}
class Database {
+Stores attack signatures
+Logs events for forensics
}
class UserInterface {
+Displays alerts (dashboard)
+Allows admin response
}
Sensor --> AnalysisEngine : "Feeds data to"
AnalysisEngine --> Database : "Updates signatures"
AnalysisEngine --> UserInterface : "Triggers alerts"4. How Intrusions Are Handled: The Response Process
When an IDS detects a threat, the incident response team follows a structured workflow:
flowchart LR
A["**Detection**\n(IDS alerts admin)"] --> B["**Analysis**\n(Is it a false positive?)"]
B -->|"Yes"| C["**Investigate Further**"]
B -->|"No"| D["**Containment**\n(Isolate affected system)"]
D --> E["**Eradication**\n(Remove malware, patch vulnerabilities)"]
E --> F["**Recovery**\n(Restore services securely)"]
F --> G["**Lessons Learned**\n(Update IDS rules, train staff)"]Real-World Example: NTC’s 2022 DDoS Attack Response
- Detection: NTC’s NIDS flagged unusual traffic spikes on their DNS servers.
- Analysis: Confirmed a DDoS attack (not a false positive) targeting government websites.
- Containment: Routed traffic through scrubbing centers to filter malicious packets.
- Eradication: Blocked IPs of attacking servers (mostly from China/Russia).
- Recovery: Restored services with rate-limiting enabled.
- Lessons Learned: Upgraded IDS to include AI-based anomaly detection.
5. Advanced IDS Techniques
A. Honeypots: Decoy Systems to Trap Attackers
A honeypot is a fake system designed to lure attackers away from real assets. Example:
- NEPSE’s fake trading terminal: If hackers try to exploit it, security teams study their methods without risking real data.
B. Machine Learning in IDS
Modern IDS use ML models to:
- Predict attacks before they happen (e.g., WhatsApp detecting sim-swap fraud patterns).
- Reduce false positives by learning normal user behavior (e.g., Khalti’s fraud detection).
6. Challenges in IDS
| Challenge | Cause | Impact | Solution |
|---|---|---|---|
| False Positives | Overly sensitive rules | Wastes admin time (e.g., flagging a Daraz bulk order as a bot) | Tune rules, use behavioral analysis. |
| False Negatives | Missing zero-day attacks | Real breaches go undetected (e.g., Pathao driver GPS spoofing) | Combine signature + anomaly detection. |
| Performance Overhead | Real-time analysis slows systems | Slower response (e.g., Ncell network lag) | Use hardware-accelerated IDS (e.g., Snort on FPGA). |
| Evasion Techniques | Attackers bypass IDS (e.g., encryption) | Undetected intrusions (e.g., WhatsApp phishing links) | Deploy hybrid IDS + endpoint protection. |
In the Real World
eSewa’s Fraud Detection
- What it uses: Anomaly-based IDS to detect unusual transaction patterns (e.g., a single user making 50 payments in 1 minute).
- How it works: If the IDS flags a transaction, eSewa’s system freezes the account and asks for OTP verification before proceeding.
- Real impact: Prevented NPR 50 million in fraud in 2023.
WhatsApp’s End-to-End Encryption + IDS
- What it uses: Behavioral IDS to detect phishing links and sim-swap attempts.
- How it works: If a user clicks a suspicious link, WhatsApp’s server-side IDS flags it and shows a warning ("This link may be unsafe").
- Real impact: Reduced account takeovers by 40% in Nepal.
NTC’s Network Security
- What it uses: Network-Based IDS (Snort/Suricata) to monitor DNS and VoIP traffic.
- How it works: During the 2022 DDoS attack, NTC’s IDS alerted admins about traffic spikes from China, allowing them to route traffic through scrubbing centers.
- Real impact: Minimized downtime for government services.
Worked Example: Detecting a SQL Injection Attack on a Daraz Order System
Scenario: A hacker tries to inject SQL code into Daraz’s login page to steal customer data.
- IDS Deployment: Daraz uses a Network-Based IDS (Snort) to monitor HTTP requests.
- Detection:
- The IDS sees a request like:
' OR '1'='1' -- - The signature-based rule matches this as a SQL injection attempt.
- The IDS sees a request like:
- Alert: The IDS sends an alert to Daraz’s security team:
[ALERT] SQL Injection Attempt Detected! Source IP: 192.168.1.100 Target: /login.php - Response:
- Containment: Daraz’s WAF (Web Application Firewall) blocks the IP.
- Eradication: The team patches the login script to sanitize inputs.
- Recovery: Services resume with enhanced IDS rules.
Exam Tip
What Examiners Want to See
✅ Definitions: Clearly distinguish between IDS, IPS, NIDS, HIDS. ✅ Architecture: Draw and explain the 4 components (Sensor → Analysis Engine → Database → UI). ✅ Detection Techniques: Compare signature vs. anomaly vs. behavioral with pros/cons. ✅ Response Process: Describe the 6-step lifecycle (Detect → Analyze → Contain → etc.). ✅ Real-World Links: Relate IDS to Nepali examples (eSewa, NTC, Ncell) or global cases (WhatsApp, Daraz). ✅ Diagrams: Always label your flowcharts (e.g., "IDS Response Workflow").
Common Mistakes to Avoid
❌ Confusing IDS and IPS: IDS detects; IPS blocks. ❌ Ignoring False Positives/Negatives: Always discuss trade-offs in detection methods. ❌ Vague Examples: Instead of "a hacker attacks," say "a DDoS on NTC’s DNS" or "SQL injection on Daraz." ❌ Skipping Legal Aspects: Mention Electronic Transactions Act 2008 and NCSC reporting.
High-Scoring Answer Structure
For a 6-mark question like "Explain the architecture of IDS":
- Introduction (1 mark): Define IDS in 1 sentence.
- Components (3 marks): Describe Sensor → Analysis Engine → Database → UI with 1 example each.
- Diagram (1 mark): Draw a labeled flowchart (use Mermaid).
- Real-World Link (1 mark): Relate to eSewa/NTC/WhatsApp.
Practice Question with Model Answer
Question: "Define Intrusion Detection System. How is an intrusion handled once detected? Explain with an example from a Nepali company."
Model Answer: An Intrusion Detection System (IDS) is a security tool that monitors network/system activities for malicious or policy-violating actions and generates alerts for administrators. Unlike an IPS, it does not block threats but enables proactive response.
Handling an Intrusion (6-Step Process):
- Detection: The IDS (e.g., Snort) flags suspicious activity (e.g., unusual login attempts).
- Analysis: Security teams verify if it’s a real threat (not a false positive).
- Containment: Affected systems are isolated (e.g., freezing a Khalti account).
- Eradication: Malware is removed, and vulnerabilities are patched.
- Recovery: Services are restored securely.
- Lessons Learned: IDS rules are updated, and staff are trained.
Example: eSewa’s Fraud Detection
- Scenario: An IDS detects 50 rapid transactions from a single Khalti account.
- Response:
- Alert: IDS flags anomalous behavior (unusual transaction volume).
- Containment: eSewa freezes the account and asks for OTP verification.
- Eradication: The team blocks the linked device IP and updates fraud rules.
- Recovery: User regains access after manual verification.
- Impact: Prevented NPR 50 million in fraud in 2023.
Diagram:
flowchart LR
A["**IDS Alert**\n(eSewa detects 50 transactions)"] --> B["**Analysis**\n(Is it fraud?)"]
B -->|"Yes"| C["**Freeze Account**\n(Containment)"]
C --> D["**Block IP**\n(Eradication)"]
D --> E["**User Verification**\n(Recovery)"]Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 8.
Discussion
Loading…