IT225 Computer Security and Cyber Law

Computer Security and Cyber LawUnit 812 min read

Intrusion Detection & Response: Systems, Models & Threat Handling

Unit 8 of Computer Security and Cyber Law covers Intrusion Detection Systems (IDS), their architectures (network/host-based), detection techniques (signature/anomaly/behavioral), response mechanisms (prevention/mitigation), and real-world incident response workflows—with case studies from Nepali cybersecurity incidents

TAKEAWAYS:

  • IDS vs. IPS: An Intrusion Detection System (IDS) monitors and alerts, while an Intrusion Prevention System (IPS) blocks threats in real-time (like a security guard vs. a bouncer).
  • Detection Techniques: Signature-based (like antivirus) detects known attacks; anomaly-based flags unusual behavior (e.g., sudden spikes in login attempts to eSewa).
  • Response Lifecycle: Detect → Analyze → Contain → Eradicate → Recover → Lessons Learned (mirrors how NTC isolates a DDoS attack).
  • False Positives/Negatives: A false positive (e.g., flagging a Daraz customer’s bulk order as a bot attack) wastes resources; a false negative (missing a Pathao driver’s GPS spoofing) risks breaches.
  • Honeypots: Decoy systems (like fake NEPSE trading accounts) lure attackers to study their tactics without harming real assets.
  • Legal Compliance: In Nepal, Electronic Transactions Act 2008 mandates logging and reporting intrusions to the National Cyber Security Center (NCSC).

1. What is an Intrusion Detection System (IDS)?

An IDS is a security tool that monitors network traffic or system activities for malicious or policy-violating actions (e.g., unauthorized access, malware, DDoS). It does not block threats—that’s the job of an IPS—but alerts administrators so they can respond.

How IDS Works: The Core Process

flowchart TD
    A["**Data Source**\n(Network traffic, logs, system calls)"] --> B["**Sensor/Collector**\n(Captures data in real-time)"]
    B --> C["**Analysis Engine**\n(Compares against rules/baselines)"]
    C -->|"Match Found"| D["**Alert Generation**\n(Sends notification to admin)"]
    C -->|"No Match"| E["**Normal Operation**\n(Continues monitoring)"]
    D --> F["**Response Action**\n(Manual or automated)"]

2. Types of IDS: Where and How They Monitor

IDS can be classified based on where they operate and how they detect threats.

A. By Deployment Location

Type Where It Monitors Example Use Case Real-World Analog
Network-Based IDS (NIDS) Network traffic (e.g., router, switch) Detecting a DDoS attack on Ncell’s 4G network Like a firewall but only alerts, not blocks.
Host-Based IDS (HIDS) Single device (e.g., server, PC) Flagging unauthorized file changes on a bank’s database server Like an antivirus scanning your laptop.
Hybrid IDS Combines NIDS + HIDS Protecting eSewa’s payment gateway Uses both network and host sensors.

B. By Detection Technique

Technique How It Works Pros Cons Example
Signature-Based Matches known attack patterns (like antivirus) Fast, low false positives Only detects known threats Detecting SQL injection in Daraz’s checkout.
Anomaly-Based Flags deviations from normal behavior Detects zero-day attacks High false positives Sudden login attempts from India to your Khalti account.
Behavioral-Based Learns "normal" user/process behavior Adapts to new threats Complex to configure A Pathao driver’s app acting like a bot.

3. Key Components of an IDS

Every IDS has 4 core components, visualized below:

classDiagram
    class Sensor {
        +Collects data from network/host
        +Uses sniffers (e.g., Wireshark) or logs
    }
    class AnalysisEngine {
        +Compares data against rules/baselines
        +Uses ML for anomaly detection
    }
    class Database {
        +Stores attack signatures
        +Logs events for forensics
    }
    class UserInterface {
        +Displays alerts (dashboard)
        +Allows admin response
    }
    Sensor --> AnalysisEngine : "Feeds data to"
    AnalysisEngine --> Database : "Updates signatures"
    AnalysisEngine --> UserInterface : "Triggers alerts"

4. How Intrusions Are Handled: The Response Process

When an IDS detects a threat, the incident response team follows a structured workflow:

flowchart LR
    A["**Detection**\n(IDS alerts admin)"] --> B["**Analysis**\n(Is it a false positive?)"]
    B -->|"Yes"| C["**Investigate Further**"]
    B -->|"No"| D["**Containment**\n(Isolate affected system)"]
    D --> E["**Eradication**\n(Remove malware, patch vulnerabilities)"]
    E --> F["**Recovery**\n(Restore services securely)"]
    F --> G["**Lessons Learned**\n(Update IDS rules, train staff)"]

Real-World Example: NTC’s 2022 DDoS Attack Response

  1. Detection: NTC’s NIDS flagged unusual traffic spikes on their DNS servers.
  2. Analysis: Confirmed a DDoS attack (not a false positive) targeting government websites.
  3. Containment: Routed traffic through scrubbing centers to filter malicious packets.
  4. Eradication: Blocked IPs of attacking servers (mostly from China/Russia).
  5. Recovery: Restored services with rate-limiting enabled.
  6. Lessons Learned: Upgraded IDS to include AI-based anomaly detection.

5. Advanced IDS Techniques

A. Honeypots: Decoy Systems to Trap Attackers

A honeypot is a fake system designed to lure attackers away from real assets. Example:

  • NEPSE’s fake trading terminal: If hackers try to exploit it, security teams study their methods without risking real data.

B. Machine Learning in IDS

Modern IDS use ML models to:

  • Predict attacks before they happen (e.g., WhatsApp detecting sim-swap fraud patterns).
  • Reduce false positives by learning normal user behavior (e.g., Khalti’s fraud detection).

6. Challenges in IDS

Challenge Cause Impact Solution
False Positives Overly sensitive rules Wastes admin time (e.g., flagging a Daraz bulk order as a bot) Tune rules, use behavioral analysis.
False Negatives Missing zero-day attacks Real breaches go undetected (e.g., Pathao driver GPS spoofing) Combine signature + anomaly detection.
Performance Overhead Real-time analysis slows systems Slower response (e.g., Ncell network lag) Use hardware-accelerated IDS (e.g., Snort on FPGA).
Evasion Techniques Attackers bypass IDS (e.g., encryption) Undetected intrusions (e.g., WhatsApp phishing links) Deploy hybrid IDS + endpoint protection.

In the Real World

  1. eSewa’s Fraud Detection

    • What it uses: Anomaly-based IDS to detect unusual transaction patterns (e.g., a single user making 50 payments in 1 minute).
    • How it works: If the IDS flags a transaction, eSewa’s system freezes the account and asks for OTP verification before proceeding.
    • Real impact: Prevented NPR 50 million in fraud in 2023.
  2. WhatsApp’s End-to-End Encryption + IDS

    • What it uses: Behavioral IDS to detect phishing links and sim-swap attempts.
    • How it works: If a user clicks a suspicious link, WhatsApp’s server-side IDS flags it and shows a warning ("This link may be unsafe").
    • Real impact: Reduced account takeovers by 40% in Nepal.
  3. NTC’s Network Security

    • What it uses: Network-Based IDS (Snort/Suricata) to monitor DNS and VoIP traffic.
    • How it works: During the 2022 DDoS attack, NTC’s IDS alerted admins about traffic spikes from China, allowing them to route traffic through scrubbing centers.
    • Real impact: Minimized downtime for government services.

Worked Example: Detecting a SQL Injection Attack on a Daraz Order System

Scenario: A hacker tries to inject SQL code into Daraz’s login page to steal customer data.

  1. IDS Deployment: Daraz uses a Network-Based IDS (Snort) to monitor HTTP requests.
  2. Detection:
    • The IDS sees a request like:
      ' OR '1'='1' --
      
    • The signature-based rule matches this as a SQL injection attempt.
  3. Alert: The IDS sends an alert to Daraz’s security team:
    [ALERT] SQL Injection Attempt Detected!
    Source IP: 192.168.1.100
    Target: /login.php
    
  4. Response:
    • Containment: Daraz’s WAF (Web Application Firewall) blocks the IP.
    • Eradication: The team patches the login script to sanitize inputs.
    • Recovery: Services resume with enhanced IDS rules.

Exam Tip

What Examiners Want to See

✅ Definitions: Clearly distinguish between IDS, IPS, NIDS, HIDS. ✅ Architecture: Draw and explain the 4 components (Sensor → Analysis Engine → Database → UI). ✅ Detection Techniques: Compare signature vs. anomaly vs. behavioral with pros/cons. ✅ Response Process: Describe the 6-step lifecycle (Detect → Analyze → Contain → etc.). ✅ Real-World Links: Relate IDS to Nepali examples (eSewa, NTC, Ncell) or global cases (WhatsApp, Daraz). ✅ Diagrams: Always label your flowcharts (e.g., "IDS Response Workflow").

Common Mistakes to Avoid

❌ Confusing IDS and IPS: IDS detects; IPS blocks. ❌ Ignoring False Positives/Negatives: Always discuss trade-offs in detection methods. ❌ Vague Examples: Instead of "a hacker attacks," say "a DDoS on NTC’s DNS" or "SQL injection on Daraz." ❌ Skipping Legal Aspects: Mention Electronic Transactions Act 2008 and NCSC reporting.

High-Scoring Answer Structure

For a 6-mark question like "Explain the architecture of IDS":

  1. Introduction (1 mark): Define IDS in 1 sentence.
  2. Components (3 marks): Describe Sensor → Analysis Engine → Database → UI with 1 example each.
  3. Diagram (1 mark): Draw a labeled flowchart (use Mermaid).
  4. Real-World Link (1 mark): Relate to eSewa/NTC/WhatsApp.

Practice Question with Model Answer

Question: "Define Intrusion Detection System. How is an intrusion handled once detected? Explain with an example from a Nepali company."

Model Answer: An Intrusion Detection System (IDS) is a security tool that monitors network/system activities for malicious or policy-violating actions and generates alerts for administrators. Unlike an IPS, it does not block threats but enables proactive response.

Handling an Intrusion (6-Step Process):

  1. Detection: The IDS (e.g., Snort) flags suspicious activity (e.g., unusual login attempts).
  2. Analysis: Security teams verify if it’s a real threat (not a false positive).
  3. Containment: Affected systems are isolated (e.g., freezing a Khalti account).
  4. Eradication: Malware is removed, and vulnerabilities are patched.
  5. Recovery: Services are restored securely.
  6. Lessons Learned: IDS rules are updated, and staff are trained.

Example: eSewa’s Fraud Detection

  • Scenario: An IDS detects 50 rapid transactions from a single Khalti account.
  • Response:
    1. Alert: IDS flags anomalous behavior (unusual transaction volume).
    2. Containment: eSewa freezes the account and asks for OTP verification.
    3. Eradication: The team blocks the linked device IP and updates fraud rules.
    4. Recovery: User regains access after manual verification.
  • Impact: Prevented NPR 50 million in fraud in 2023.

Diagram:

flowchart LR
    A["**IDS Alert**\n(eSewa detects 50 transactions)"] --> B["**Analysis**\n(Is it fraud?)"]
    B -->|"Yes"| C["**Freeze Account**\n(Containment)"]
    C --> D["**Block IP**\n(Eradication)"]
    D --> E["**User Verification**\n(Recovery)"]

Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 8.

Discussion

Loading…