Network SecurityUnit 318 min read
Intrusion Detection Systems (IDS): Types, Approaches & Real-World Applications
Unit 3 of Network Security explores how Intrusion Detection Systems (IDS) monitor networks for malicious activities, covering signature-based vs. anomaly-based detection, deployment models (NIDS/HIDS), and real-world use cases like eSewa fraud prevention and Ncell network security.
TAKEAWAYS:
- IDS detects unauthorized access or attacks by analyzing network traffic or system logs using signature-based (rule-matching) or anomaly-based (behavioral) methods.
- Network-based IDS (NIDS) monitors traffic across entire networks (e.g., NTC’s backbone), while Host-based IDS (HIDS) focuses on single devices (e.g., Daraz servers).
- False positives/negatives are critical trade-offs: signature-based IDS misses zero-day attacks, while anomaly-based IDS triggers alerts for normal but unusual activity.
- Deployment strategies (inline vs. passive) and response mechanisms (logging, blocking, or alerting) determine an IDS’s effectiveness in real-world scenarios like Pathao’s ride-hailing security.
- Hybrid IDS combines multiple techniques (e.g., machine learning + rule-based) to improve accuracy, used by banks like NMB to detect fraudulent transactions.
- IDS vs. IPS: IDS detects threats, while Intrusion Prevention Systems (IPS) actively block them—critical for high-risk systems like NEPSE’s trading platforms.
1. What is an Intrusion?
An intrusion is any unauthorized attempt to access, manipulate, or disrupt a system or network. Intrusions can be:
- External: Attacks from outside the network (e.g., hackers exploiting vulnerabilities in eSewa’s API).
- Internal: Insider threats (e.g., an employee leaking customer data from a bank’s database).
- Malicious vs. Non-malicious: Accidental misconfigurations (e.g., misrouted traffic in NTC’s network) or deliberate attacks (e.g., DDoS on a government website).
Why is detection hard? Attackers use evasion techniques like:
- Encryption (hiding malicious payloads in TLS traffic).
- Fragmentation (splitting packets to bypass signature checks).
- Polymorphic code (changing attack signatures dynamically).
2. How Intrusion Detection Systems (IDS) Work
IDS monitors system activities for policy violations or malicious behavior. It operates in two primary modes:
A. Signature-Based Detection (Misuse Detection)
- How it works: Compares network traffic/system logs against a database of known attack patterns (signatures).
- Example signatures:
- SQL injection strings (
' OR 1=1 --). - Malware hashes (e.g.,
MD5: a1b2c3...for ransomware). - Exploit kits (e.g., EternalBlue used in WannaCry).
- SQL injection strings (
sequenceDiagram
participant User as Attacker
participant IDS as Signature-Based IDS
participant DB as Signature Database
User->>IDS: Sends malicious packet (e.g., SQLi)
IDS->>DB: Checks for matching signature
DB-->>IDS: Returns "Match found: SQLi pattern"
IDS->>Admin: Alerts administratorAdvantages:
- Low false positive rate (only flags known threats).
- Fast and resource-efficient.
Disadvantages:
- Cannot detect zero-day attacks (new, unknown threats).
- Requires frequent signature updates (e.g., Snort rules).
Real-World Example:
- eSewa uses signature-based IDS to block known phishing links in payment transactions. When a user clicks a suspicious URL, the IDS checks it against a blacklist of fraudulent domains.
B. Anomaly-Based Detection (Behavioral Detection)
- How it works: Learns "normal" behavior (baseline) and flags deviations (e.g., sudden spikes in traffic or unusual login times).
- Techniques:
- Statistical analysis (e.g., mean/standard deviation of packet sizes).
- Machine learning (e.g., clustering normal vs. abnormal traffic).
- Rule-based thresholds (e.g., "Alert if >10 failed login attempts in 5 minutes").
stateDiagram-v2
[*] --> Normal: Traffic within baseline
Normal --> Anomaly: Deviation detected (e.g., traffic spike)
Anomaly --> Alert: IDS triggers notification
Anomaly --> Block: (Optional) IPS blocks trafficAdvantages:
- Detects unknown (zero-day) attacks.
- Adapts to evolving threats (e.g., AI-driven fraud in Khalti).
Disadvantages:
- High false positive rate (normal but unusual activity may trigger alerts).
- Requires training data to establish baselines.
Real-World Example:
- Ncell uses anomaly-based IDS to detect SIM-box fraud. If a single SIM suddenly routes calls to 100+ international numbers (unusual behavior), the IDS flags it for investigation.
C. Hybrid Detection
Combines signature-based + anomaly-based methods for better accuracy. Example: A bank like NMB might use:
- Signature-based IDS to block known malware.
- Anomaly-based IDS to detect unusual transaction patterns (e.g., a customer suddenly transferring $10,000 to a new account).
3. Types of IDS Based on Deployment
IDS can be classified based on where they monitor activity:
| Type | Deployment | Example Use Case | Pros | Cons |
|---|---|---|---|---|
| Network-based IDS (NIDS) | Monitors entire network traffic (e.g., router, switch). | Protecting NTC’s fiber-optic backbone. | Covers all devices on the network. | High false positives; can’t see encrypted traffic. |
| Host-based IDS (HIDS) | Installed on individual devices (e.g., servers, workstations). | Securing Daraz’s order-processing servers. | Detects internal threats (e.g., rootkits). | Limited to one host; high resource usage. |
| Wireless IDS (WIDS) | Monitors wireless networks (e.g., IEEE 802.11). | Securing a university’s Wi-Fi (e.g., TU’s campus network). | Detects rogue APs or evil twin attacks. | Limited range; signal interference issues. |
| Protocol-based IDS | Focuses on specific protocols (e.g., HTTP, FTP). | Blocking malicious HTTP requests to a website. | Deep inspection of protocol layers. | Complex to configure; protocol-specific. |
4. IDS vs. IPS: Key Differences
While IDS detects intrusions, Intrusion Prevention Systems (IPS) take automated action (e.g., blocking traffic).
| Feature | Intrusion Detection System (IDS) | Intrusion Prevention System (IPS) |
|---|---|---|
| Primary Role | Monitors and alerts. | Monitors, alerts, and blocks threats. |
| Deployment | Passive (does not interfere with traffic). | Inline (acts as a firewall). |
| Response | Logs alerts for administrators. | Automatically drops/blocks malicious traffic. |
| Example | Snort (in detection mode). | Snort (in inline mode) or Cisco Firepower. |
| Use Case | Low-risk environments (e.g., university labs). | High-risk environments (e.g., NEPSE trading systems). |
Real-World Example:
- Pathao uses an IPS to block fraudulent ride requests in real time. If an IDS detects a suspicious pattern (e.g., a bot spamming ride requests), the IPS drops those packets before they reach the server.
5. IDS Architectures and Components
A typical IDS consists of:
classDiagram
class Sensor {
+Collects data (packets/logs)
}
class Analyzer {
+Processes data (signature/anomaly detection)
}
class Database {
+Stores signatures/baselines
}
class Console {
+Displays alerts/visualizations
}
Sensor --> Analyzer : "Feeds data to"
Analyzer --> Database : "Queries for signatures"
Analyzer --> Console : "Sends alerts to"
Console --> Admin : "Notifies administrator"Key Components:
- Sensors: Capture network traffic or system logs (e.g., placed on routers or endpoints).
- Analyzers: Process data using detection methods (signature/anomaly).
- Database: Stores attack signatures, user profiles, and baselines.
- Console: Provides a dashboard for administrators (e.g., SIEM tools like Splunk).
6. IDS Evasion Techniques and Countermeasures
Attackers use techniques to bypass IDS. Here’s how they work and how to counter them:
| Evasion Technique | How It Works | Countermeasure |
|---|---|---|
| Encryption | Hides malicious payloads in TLS/SSL. | Deploy SSL inspection (decrypts traffic for inspection). |
| Fragmentation | Splits packets to avoid signature matches. | Enable reassembly in IDS (e.g., Snort’s fragmented_ip rule). |
| Protocol Violations | Sends malformed packets to confuse IDS. | Use stateful inspection (tracks protocol states). |
| Timing Attacks | Delays or speeds up traffic to evade detection. | Implement rate-limiting and time-based analysis. |
| Polymorphic Code | Changes attack signatures dynamically. | Use behavioral analysis (anomaly-based detection). |
Worked Example: Scenario: A hacker targets Khalti’s payment gateway by sending fragmented packets containing a SQL injection payload. Evasion: The IDS (configured in signature mode) misses the attack because the payload is split across multiple fragments. Countermeasure:
- Enable packet reassembly in the IDS (e.g., Snort rule:
reassemble_ip_only). - Use deep packet inspection (DPI) to analyze payloads before reassembly.
7. Real-World Applications of IDS
A. E-Commerce: Daraz and Fraud Prevention
- Problem: Fake orders, credit card fraud, and account takeovers.
- Solution: Daraz deploys a hybrid IDS:
- Signature-based: Blocks known fraudulent IPs (e.g., from dark web markets).
- Anomaly-based: Flags unusual ordering patterns (e.g., 100 identical items ordered in 1 minute).
- Result: Reduces fraudulent transactions by ~40%.
Daraz logo (Image: www.daraz.com.bd, Public domain, via Wikimedia Commons)
B. Banking: NMB and Transaction Monitoring
- Problem: Insider threats and automated bots draining accounts.
- Solution: NMB uses HIDS on ATMs and servers to:
- Detect unusual login times (e.g., a teller logging in at 3 AM).
- Monitor transaction anomalies (e.g., sudden large withdrawals).
- Result: Early detection of $2M fraud attempt in 2022.
NMB Bank logo (Image: Bahati Abraham Kombe, CC BY-SA 4.0, via Wikimedia Commons)
C. Government: NTC and Network Security
- Problem: DDoS attacks on critical infrastructure (e.g., fiber-optic networks).
- Solution: NTC deploys NIDS at key nodes to:
- Detect traffic flooding (e.g., >10,000 packets/second from a single IP).
- Block malicious traffic using inline IPS.
- Result: Mitigated a major DDoS attack during a national election.
D. Ride-Hailing: Pathao and Bot Detection
- Problem: Fake accounts and bots inflating driver counts.
- Solution: Pathao uses anomaly-based IDS to:
- Detect unusual GPS patterns (e.g., a "driver" moving at 200 km/h).
- Flag suspicious login locations (e.g., a user logging in from 10 countries in 1 hour).
- Result: Reduced fake accounts by ~30%.
Pathao logo (Image: pathao.inc, CC BY-SA 4.0, via Wikimedia Commons)
8. Popular IDS Tools
| Tool | Type | Key Features | Use Case |
|---|---|---|---|
| Snort | NIDS/HIDS | Open-source, signature/anomaly-based. | Small to medium networks (e.g., universities). |
| Suricata | NIDS/IPS | High performance, multi-threaded. | Enterprise networks (e.g., banks). |
| OSSEC | HIDS | File integrity monitoring, log analysis. | Server security (e.g., Daraz databases). |
| Zeek (Bro) | NIDS | Protocol-aware, generates detailed logs. | Security research and forensics. |
| Splunk | SIEM (IDS + Analytics) | Correlates logs from multiple sources. | Large-scale monitoring (e.g., NTC). |
9. Challenges and Limitations of IDS
False Positives/Negatives:
- False positives: Legitimate traffic flagged as malicious (e.g., a security researcher testing tools).
- False negatives: Actual attacks missed (e.g., a zero-day exploit).
- Solution: Tune detection rules and use human review for critical alerts.
Performance Overhead:
- Deep packet inspection can slow down networks.
- Solution: Deploy IDS on high-performance hardware or use sampling (inspect a subset of traffic).
Encrypted Traffic:
- IDS cannot inspect TLS-encrypted traffic without decryption keys.
- Solution: Use SSL inspection (but risks privacy concerns).
Evolving Threats:
- Attackers adapt to bypass IDS (e.g., fileless malware).
- Solution: Combine IDS with endpoint detection (EDR) and AI-driven analysis.
10. IDS in the Cloud and IoT
A. Cloud Security (AWS, Google Cloud)
- Challenge: Dynamic, scalable environments make traditional IDS hard to deploy.
- Solution:
- AWS GuardDuty: Monitors AWS accounts for malicious activity.
- CloudTrail + SIEM: Logs API calls and triggers alerts for anomalies.
B. IoT Security (Smart Homes, Industrial IoT)
- Challenge: IoT devices often have weak security (e.g., default passwords).
- Solution:
- Network-based IDS: Monitors IoT traffic for unusual commands (e.g., a smart camera sending data to a suspicious IP).
- Behavioral Analysis: Detects botnet C&C traffic (e.g., Mirai malware).
Real-World Example:
- Nepal’s smart grid projects use IDS to detect unauthorized access to SCADA systems controlling electricity distribution.
Exam Tip
How to Score Full Marks in TU/PU Exams
Define Clearly:
- Start with precise definitions (e.g., "An Intrusion Detection System (IDS) is a device or software application that monitors a network or system for malicious activity or policy violations.").
Compare and Contrast:
- Exams often ask to differentiate between NIDS vs. HIDS or signature-based vs. anomaly-based IDS. Use tables (like the one above) to organize your answer.
Use Real-World Examples:
- Link concepts to Nepali companies (e.g., "Like Ncell uses anomaly-based IDS to detect SIM-box fraud, banks use HIDS to monitor transaction logs.").
- Worked examples (e.g., "If an IDS detects a SQL injection attempt on eSewa’s payment gateway, it would trigger an alert based on the signature
UNION SELECT.") earn extra marks.
Diagrams and Flowcharts:
- Draw sequence diagrams for detection processes (e.g., how a packet is analyzed).
- Use state diagrams to explain anomaly detection (normal → anomaly → alert).
Common Pitfalls to Avoid:
- ❌ Confusing IDS (detection) with IPS (prevention).
- ❌ Forgetting to mention false positives/negatives in discussions.
- ❌ Ignoring real-world constraints (e.g., encrypted traffic limitations).
Short-Answer Tips:
- For "How can IDS secure a network?", structure your answer as:
- Monitoring (capturing traffic/logs).
- Analysis (signature/anomaly detection).
- Response (alerting or blocking).
- Example (e.g., "Like NTC uses NIDS to detect DDoS attacks.").
- For "How can IDS secure a network?", structure your answer as:
Sample Exam Question and Model Answer
Question: "Discuss the different approaches of intrusion detection with examples. How would you deploy an IDS for a bank like NMB?"
Model Answer: Intrusion Detection Systems (IDS) employ two primary approaches:
Signature-Based Detection:
- How it works: Compares network traffic against a database of known attack patterns (e.g., malware hashes, exploit signatures).
- Example: If a user attempts to log in to NMB’s online banking with credentials matching a brute-force attack signature, the IDS alerts the administrator.
- Limitation: Cannot detect zero-day attacks (e.g., a new ransomware variant).
Anomaly-Based Detection:
- How it works: Learns normal behavior (e.g., typical transaction amounts, login times) and flags deviations.
- Example: If a customer suddenly transfers $50,000 (unusual for their account), the IDS triggers an alert.
- Limitation: High false positives (e.g., a customer traveling abroad may trigger alerts for "unusual locations").
Deployment for NMB: To secure NMB’s network, I would deploy a hybrid IDS with the following components:
- Network-Based IDS (NIDS):
- Placed at the perimeter (e.g., between NMB’s firewall and internal network) to monitor all incoming/outgoing traffic.
- Uses signature-based rules to block known malware (e.g., Emotet) and anomaly detection to flag unusual transaction patterns.
- Host-Based IDS (HIDS):
- Installed on critical servers (e.g., databases, ATMs) to detect insider threats (e.g., a database administrator accessing unauthorized tables).
- Monitors file integrity (e.g., detecting changes to critical binaries).
- Wireless IDS (WIDS):
- Deployed in bank branches to detect rogue Wi-Fi hotspots (e.g., an attacker setting up a fake "NMB_WiFi" network to steal credentials).
- Response Mechanism:
- Inline IPS: For high-risk areas (e.g., trading systems), use an IPS to automatically block detected threats.
- SIEM Integration: Correlate IDS alerts with logs from firewalls, endpoints, and applications (e.g., using Splunk) for a unified view.
Visualization of Deployment:
graph TD
A["Internet"] --> B["Firewall"]
B --> C["NIDS: Snort/Suricata"]
C --> D["Internal Network"]
D --> E["Servers with HIDS"]
E --> F["Database"]
G["Wireless Clients"] --> H["WIDS: AIROPEEK"]
H --> D
C --> I["SIEM: Splunk"]
I --> J["Security Team"]Why This Works for NMB:
- Layered defense: Combines network, host, and wireless monitoring.
- Balanced approach: Uses signature-based for known threats and anomaly-based for unknown risks.
- Automated response: Critical systems (e.g., trading) use IPS to prevent attacks in real time.
- Compliance: Meets PCI-DSS requirements for financial institutions.
Final Checklist for Exam Preparation
| Topic | Key Points to Remember | Visual Aid |
|---|---|---|
| Definitions | IDS vs. IPS, signature vs. anomaly detection. | Comparison table. |
| Deployment Types | NIDS, HIDS, WIDS, protocol-based. | Mermaid class diagram. |
| Evasion Techniques | Encryption, fragmentation, polymorphic code. | Table with countermeasures. |
| Real-World Examples | eSewa (signature), Ncell (anomaly), NMB (hybrid). | Sequence diagram of detection flow. |
| Tools | Snort, Suricata, OSSEC, Splunk. | Tool feature comparison table. |
Based on the TU BSc CSIT syllabus for Network Security (CSC416), unit 3.
Discussion
Loading…