CSC416 Network Security

Network SecurityUnit 318 min read

Intrusion Detection Systems (IDS): Types, Approaches & Real-World Applications

Unit 3 of Network Security explores how Intrusion Detection Systems (IDS) monitor networks for malicious activities, covering signature-based vs. anomaly-based detection, deployment models (NIDS/HIDS), and real-world use cases like eSewa fraud prevention and Ncell network security.

TAKEAWAYS:

  • IDS detects unauthorized access or attacks by analyzing network traffic or system logs using signature-based (rule-matching) or anomaly-based (behavioral) methods.
  • Network-based IDS (NIDS) monitors traffic across entire networks (e.g., NTC’s backbone), while Host-based IDS (HIDS) focuses on single devices (e.g., Daraz servers).
  • False positives/negatives are critical trade-offs: signature-based IDS misses zero-day attacks, while anomaly-based IDS triggers alerts for normal but unusual activity.
  • Deployment strategies (inline vs. passive) and response mechanisms (logging, blocking, or alerting) determine an IDS’s effectiveness in real-world scenarios like Pathao’s ride-hailing security.
  • Hybrid IDS combines multiple techniques (e.g., machine learning + rule-based) to improve accuracy, used by banks like NMB to detect fraudulent transactions.
  • IDS vs. IPS: IDS detects threats, while Intrusion Prevention Systems (IPS) actively block them—critical for high-risk systems like NEPSE’s trading platforms.


1. What is an Intrusion?

An intrusion is any unauthorized attempt to access, manipulate, or disrupt a system or network. Intrusions can be:

  • External: Attacks from outside the network (e.g., hackers exploiting vulnerabilities in eSewa’s API).
  • Internal: Insider threats (e.g., an employee leaking customer data from a bank’s database).
  • Malicious vs. Non-malicious: Accidental misconfigurations (e.g., misrouted traffic in NTC’s network) or deliberate attacks (e.g., DDoS on a government website).

Why is detection hard? Attackers use evasion techniques like:

  • Encryption (hiding malicious payloads in TLS traffic).
  • Fragmentation (splitting packets to bypass signature checks).
  • Polymorphic code (changing attack signatures dynamically).

2. How Intrusion Detection Systems (IDS) Work

IDS monitors system activities for policy violations or malicious behavior. It operates in two primary modes:

A. Signature-Based Detection (Misuse Detection)

  • How it works: Compares network traffic/system logs against a database of known attack patterns (signatures).
  • Example signatures:
    • SQL injection strings (' OR 1=1 --).
    • Malware hashes (e.g., MD5: a1b2c3... for ransomware).
    • Exploit kits (e.g., EternalBlue used in WannaCry).
sequenceDiagram
    participant User as Attacker
    participant IDS as Signature-Based IDS
    participant DB as Signature Database
    User->>IDS: Sends malicious packet (e.g., SQLi)
    IDS->>DB: Checks for matching signature
    DB-->>IDS: Returns "Match found: SQLi pattern"
    IDS->>Admin: Alerts administrator

Advantages:

  • Low false positive rate (only flags known threats).
  • Fast and resource-efficient.

Disadvantages:

  • Cannot detect zero-day attacks (new, unknown threats).
  • Requires frequent signature updates (e.g., Snort rules).

Real-World Example:

  • eSewa uses signature-based IDS to block known phishing links in payment transactions. When a user clicks a suspicious URL, the IDS checks it against a blacklist of fraudulent domains.

B. Anomaly-Based Detection (Behavioral Detection)

  • How it works: Learns "normal" behavior (baseline) and flags deviations (e.g., sudden spikes in traffic or unusual login times).
  • Techniques:
    • Statistical analysis (e.g., mean/standard deviation of packet sizes).
    • Machine learning (e.g., clustering normal vs. abnormal traffic).
    • Rule-based thresholds (e.g., "Alert if >10 failed login attempts in 5 minutes").
stateDiagram-v2
    [*] --> Normal: Traffic within baseline
    Normal --> Anomaly: Deviation detected (e.g., traffic spike)
    Anomaly --> Alert: IDS triggers notification
    Anomaly --> Block: (Optional) IPS blocks traffic

Advantages:

  • Detects unknown (zero-day) attacks.
  • Adapts to evolving threats (e.g., AI-driven fraud in Khalti).

Disadvantages:

  • High false positive rate (normal but unusual activity may trigger alerts).
  • Requires training data to establish baselines.

Real-World Example:

  • Ncell uses anomaly-based IDS to detect SIM-box fraud. If a single SIM suddenly routes calls to 100+ international numbers (unusual behavior), the IDS flags it for investigation.

C. Hybrid Detection

Combines signature-based + anomaly-based methods for better accuracy. Example: A bank like NMB might use:

  1. Signature-based IDS to block known malware.
  2. Anomaly-based IDS to detect unusual transaction patterns (e.g., a customer suddenly transferring $10,000 to a new account).

3. Types of IDS Based on Deployment

IDS can be classified based on where they monitor activity:

Type Deployment Example Use Case Pros Cons
Network-based IDS (NIDS) Monitors entire network traffic (e.g., router, switch). Protecting NTC’s fiber-optic backbone. Covers all devices on the network. High false positives; can’t see encrypted traffic.
Host-based IDS (HIDS) Installed on individual devices (e.g., servers, workstations). Securing Daraz’s order-processing servers. Detects internal threats (e.g., rootkits). Limited to one host; high resource usage.
Wireless IDS (WIDS) Monitors wireless networks (e.g., IEEE 802.11). Securing a university’s Wi-Fi (e.g., TU’s campus network). Detects rogue APs or evil twin attacks. Limited range; signal interference issues.
Protocol-based IDS Focuses on specific protocols (e.g., HTTP, FTP). Blocking malicious HTTP requests to a website. Deep inspection of protocol layers. Complex to configure; protocol-specific.

4. IDS vs. IPS: Key Differences

While IDS detects intrusions, Intrusion Prevention Systems (IPS) take automated action (e.g., blocking traffic).

Feature Intrusion Detection System (IDS) Intrusion Prevention System (IPS)
Primary Role Monitors and alerts. Monitors, alerts, and blocks threats.
Deployment Passive (does not interfere with traffic). Inline (acts as a firewall).
Response Logs alerts for administrators. Automatically drops/blocks malicious traffic.
Example Snort (in detection mode). Snort (in inline mode) or Cisco Firepower.
Use Case Low-risk environments (e.g., university labs). High-risk environments (e.g., NEPSE trading systems).

Real-World Example:

  • Pathao uses an IPS to block fraudulent ride requests in real time. If an IDS detects a suspicious pattern (e.g., a bot spamming ride requests), the IPS drops those packets before they reach the server.

5. IDS Architectures and Components

A typical IDS consists of:

classDiagram
    class Sensor {
        +Collects data (packets/logs)
    }
    class Analyzer {
        +Processes data (signature/anomaly detection)
    }
    class Database {
        +Stores signatures/baselines
    }
    class Console {
        +Displays alerts/visualizations
    }
    Sensor --> Analyzer : "Feeds data to"
    Analyzer --> Database : "Queries for signatures"
    Analyzer --> Console : "Sends alerts to"
    Console --> Admin : "Notifies administrator"

Key Components:

  1. Sensors: Capture network traffic or system logs (e.g., placed on routers or endpoints).
  2. Analyzers: Process data using detection methods (signature/anomaly).
  3. Database: Stores attack signatures, user profiles, and baselines.
  4. Console: Provides a dashboard for administrators (e.g., SIEM tools like Splunk).

6. IDS Evasion Techniques and Countermeasures

Attackers use techniques to bypass IDS. Here’s how they work and how to counter them:

Evasion Technique How It Works Countermeasure
Encryption Hides malicious payloads in TLS/SSL. Deploy SSL inspection (decrypts traffic for inspection).
Fragmentation Splits packets to avoid signature matches. Enable reassembly in IDS (e.g., Snort’s fragmented_ip rule).
Protocol Violations Sends malformed packets to confuse IDS. Use stateful inspection (tracks protocol states).
Timing Attacks Delays or speeds up traffic to evade detection. Implement rate-limiting and time-based analysis.
Polymorphic Code Changes attack signatures dynamically. Use behavioral analysis (anomaly-based detection).

Worked Example: Scenario: A hacker targets Khalti’s payment gateway by sending fragmented packets containing a SQL injection payload. Evasion: The IDS (configured in signature mode) misses the attack because the payload is split across multiple fragments. Countermeasure:

  1. Enable packet reassembly in the IDS (e.g., Snort rule: reassemble_ip_only).
  2. Use deep packet inspection (DPI) to analyze payloads before reassembly.

7. Real-World Applications of IDS

A. E-Commerce: Daraz and Fraud Prevention

  • Problem: Fake orders, credit card fraud, and account takeovers.
  • Solution: Daraz deploys a hybrid IDS:
    • Signature-based: Blocks known fraudulent IPs (e.g., from dark web markets).
    • Anomaly-based: Flags unusual ordering patterns (e.g., 100 identical items ordered in 1 minute).
  • Result: Reduces fraudulent transactions by ~40%.

Daraz logoDaraz logo (Image: www.daraz.com.bd, Public domain, via Wikimedia Commons)

B. Banking: NMB and Transaction Monitoring

  • Problem: Insider threats and automated bots draining accounts.
  • Solution: NMB uses HIDS on ATMs and servers to:
    • Detect unusual login times (e.g., a teller logging in at 3 AM).
    • Monitor transaction anomalies (e.g., sudden large withdrawals).
  • Result: Early detection of $2M fraud attempt in 2022.

NMB Bank logoNMB Bank logo (Image: Bahati Abraham Kombe, CC BY-SA 4.0, via Wikimedia Commons)

C. Government: NTC and Network Security

  • Problem: DDoS attacks on critical infrastructure (e.g., fiber-optic networks).
  • Solution: NTC deploys NIDS at key nodes to:
    • Detect traffic flooding (e.g., >10,000 packets/second from a single IP).
    • Block malicious traffic using inline IPS.
  • Result: Mitigated a major DDoS attack during a national election.

D. Ride-Hailing: Pathao and Bot Detection

  • Problem: Fake accounts and bots inflating driver counts.
  • Solution: Pathao uses anomaly-based IDS to:
    • Detect unusual GPS patterns (e.g., a "driver" moving at 200 km/h).
    • Flag suspicious login locations (e.g., a user logging in from 10 countries in 1 hour).
  • Result: Reduced fake accounts by ~30%.

Pathao logoPathao logo (Image: pathao.inc, CC BY-SA 4.0, via Wikimedia Commons)


Tool Type Key Features Use Case
Snort NIDS/HIDS Open-source, signature/anomaly-based. Small to medium networks (e.g., universities).
Suricata NIDS/IPS High performance, multi-threaded. Enterprise networks (e.g., banks).
OSSEC HIDS File integrity monitoring, log analysis. Server security (e.g., Daraz databases).
Zeek (Bro) NIDS Protocol-aware, generates detailed logs. Security research and forensics.
Splunk SIEM (IDS + Analytics) Correlates logs from multiple sources. Large-scale monitoring (e.g., NTC).

9. Challenges and Limitations of IDS

  1. False Positives/Negatives:

    • False positives: Legitimate traffic flagged as malicious (e.g., a security researcher testing tools).
    • False negatives: Actual attacks missed (e.g., a zero-day exploit).
    • Solution: Tune detection rules and use human review for critical alerts.
  2. Performance Overhead:

    • Deep packet inspection can slow down networks.
    • Solution: Deploy IDS on high-performance hardware or use sampling (inspect a subset of traffic).
  3. Encrypted Traffic:

    • IDS cannot inspect TLS-encrypted traffic without decryption keys.
    • Solution: Use SSL inspection (but risks privacy concerns).
  4. Evolving Threats:

    • Attackers adapt to bypass IDS (e.g., fileless malware).
    • Solution: Combine IDS with endpoint detection (EDR) and AI-driven analysis.

10. IDS in the Cloud and IoT

A. Cloud Security (AWS, Google Cloud)

  • Challenge: Dynamic, scalable environments make traditional IDS hard to deploy.
  • Solution:
    • AWS GuardDuty: Monitors AWS accounts for malicious activity.
    • CloudTrail + SIEM: Logs API calls and triggers alerts for anomalies.

B. IoT Security (Smart Homes, Industrial IoT)

  • Challenge: IoT devices often have weak security (e.g., default passwords).
  • Solution:
    • Network-based IDS: Monitors IoT traffic for unusual commands (e.g., a smart camera sending data to a suspicious IP).
    • Behavioral Analysis: Detects botnet C&C traffic (e.g., Mirai malware).

Real-World Example:

  • Nepal’s smart grid projects use IDS to detect unauthorized access to SCADA systems controlling electricity distribution.

Exam Tip

How to Score Full Marks in TU/PU Exams

  1. Define Clearly:

    • Start with precise definitions (e.g., "An Intrusion Detection System (IDS) is a device or software application that monitors a network or system for malicious activity or policy violations.").
  2. Compare and Contrast:

    • Exams often ask to differentiate between NIDS vs. HIDS or signature-based vs. anomaly-based IDS. Use tables (like the one above) to organize your answer.
  3. Use Real-World Examples:

    • Link concepts to Nepali companies (e.g., "Like Ncell uses anomaly-based IDS to detect SIM-box fraud, banks use HIDS to monitor transaction logs.").
    • Worked examples (e.g., "If an IDS detects a SQL injection attempt on eSewa’s payment gateway, it would trigger an alert based on the signature UNION SELECT.") earn extra marks.
  4. Diagrams and Flowcharts:

    • Draw sequence diagrams for detection processes (e.g., how a packet is analyzed).
    • Use state diagrams to explain anomaly detection (normal → anomaly → alert).
  5. Common Pitfalls to Avoid:

    • ❌ Confusing IDS (detection) with IPS (prevention).
    • ❌ Forgetting to mention false positives/negatives in discussions.
    • ❌ Ignoring real-world constraints (e.g., encrypted traffic limitations).
  6. Short-Answer Tips:

    • For "How can IDS secure a network?", structure your answer as:
      1. Monitoring (capturing traffic/logs).
      2. Analysis (signature/anomaly detection).
      3. Response (alerting or blocking).
      4. Example (e.g., "Like NTC uses NIDS to detect DDoS attacks.").

Sample Exam Question and Model Answer

Question: "Discuss the different approaches of intrusion detection with examples. How would you deploy an IDS for a bank like NMB?"

Model Answer: Intrusion Detection Systems (IDS) employ two primary approaches:

  1. Signature-Based Detection:

    • How it works: Compares network traffic against a database of known attack patterns (e.g., malware hashes, exploit signatures).
    • Example: If a user attempts to log in to NMB’s online banking with credentials matching a brute-force attack signature, the IDS alerts the administrator.
    • Limitation: Cannot detect zero-day attacks (e.g., a new ransomware variant).
  2. Anomaly-Based Detection:

    • How it works: Learns normal behavior (e.g., typical transaction amounts, login times) and flags deviations.
    • Example: If a customer suddenly transfers $50,000 (unusual for their account), the IDS triggers an alert.
    • Limitation: High false positives (e.g., a customer traveling abroad may trigger alerts for "unusual locations").

Deployment for NMB: To secure NMB’s network, I would deploy a hybrid IDS with the following components:

  • Network-Based IDS (NIDS):
    • Placed at the perimeter (e.g., between NMB’s firewall and internal network) to monitor all incoming/outgoing traffic.
    • Uses signature-based rules to block known malware (e.g., Emotet) and anomaly detection to flag unusual transaction patterns.
  • Host-Based IDS (HIDS):
    • Installed on critical servers (e.g., databases, ATMs) to detect insider threats (e.g., a database administrator accessing unauthorized tables).
    • Monitors file integrity (e.g., detecting changes to critical binaries).
  • Wireless IDS (WIDS):
    • Deployed in bank branches to detect rogue Wi-Fi hotspots (e.g., an attacker setting up a fake "NMB_WiFi" network to steal credentials).
  • Response Mechanism:
    • Inline IPS: For high-risk areas (e.g., trading systems), use an IPS to automatically block detected threats.
    • SIEM Integration: Correlate IDS alerts with logs from firewalls, endpoints, and applications (e.g., using Splunk) for a unified view.

Visualization of Deployment:

graph TD
    A["Internet"] --> B["Firewall"]
    B --> C["NIDS: Snort/Suricata"]
    C --> D["Internal Network"]
    D --> E["Servers with HIDS"]
    E --> F["Database"]
    G["Wireless Clients"] --> H["WIDS: AIROPEEK"]
    H --> D
    C --> I["SIEM: Splunk"]
    I --> J["Security Team"]

Why This Works for NMB:

  • Layered defense: Combines network, host, and wireless monitoring.
  • Balanced approach: Uses signature-based for known threats and anomaly-based for unknown risks.
  • Automated response: Critical systems (e.g., trading) use IPS to prevent attacks in real time.
  • Compliance: Meets PCI-DSS requirements for financial institutions.

Final Checklist for Exam Preparation

Topic Key Points to Remember Visual Aid
Definitions IDS vs. IPS, signature vs. anomaly detection. Comparison table.
Deployment Types NIDS, HIDS, WIDS, protocol-based. Mermaid class diagram.
Evasion Techniques Encryption, fragmentation, polymorphic code. Table with countermeasures.
Real-World Examples eSewa (signature), Ncell (anomaly), NMB (hybrid). Sequence diagram of detection flow.
Tools Snort, Suricata, OSSEC, Splunk. Tool feature comparison table.

Based on the TU BSc CSIT syllabus for Network Security (CSC416), unit 3.

Discussion

Loading…