Home > Ask the Security Experts > Network Security Questions & Answers > What is the cause of an 'intrusion attempt' message?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What is the cause of an 'intrusion attempt' message?

Mike Chapple, featured expert EXPERT RESPONSE FROM: Mike Chapple, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 25 October 2008
We have about 25 computers on our network. All have client antivirus security installed. Today, on several of them, I received a pop-up stating that an intrusion attempt has been blocked. This is the first time that I received this message. What could be some possible causes for this?

>
First, the good news. The message you received indicates that your endpoint security product is working properly. It detected and blocked the intrusion attempt, ensuring the security of that system.

There are three likely scenarios that could have caused this message to appear:

  • First, in the best case, it's a false alarm. Intrusion detection systems (IDSes) often generate false positive alerts. In order to determine if this is the case on your systems, you'll have to look at the details of the alerts and determine whether the packets triggering the alerts appear to be legitimate activity for your environment. What may be considered a legitimate packet on one network could be a rogue packet on another.
  • The second possibility is that the intrusion attempt came from an infected system on the local network. If this is the case, the alert should still provide you with valuable information: the address of the system causing the alert. You should check that system for any signs of malicious activity.
  • The final possibility is that your systems received the attack from outside your local network. In this case, you likely have a misconfiguration on your network firewall that allowed the traffic to reach the endpoint. Check your configuration and ensure that external traffic is not allowed into networks hosting endpoint systems without the use of a VPN.

Good luck tracking down the source of this attack!

More information:

  • A SearchSecurity.com reader asks Mike Chapple, "What are the differences between intrusion detection and intrusion prevention?"
  • Learn the best practices for creating an IDS and maintaining a signature database.


  • BROWSE BY TAG
    Network Security,   Network Intrusion Detection (IDS),   Network Intrusion Detection and Analysis,   Enterprise Network Security,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Network Security
    How to set up a split-tunnel VPN in Windows Vista
    What is the difference between static and dynamic network validation?
    Port scan attack prevention best practices
    Securing the intranet with remote access VPN security
    How to prevent network sniffing and eavesdropping
    How to implement virtual firewalls in a complex network infrastructure
    How to manage network bandwidth with distributed ISP bandwidth
    How to edit group policy objects to give a user local admin rights
    How to prevent operating system cloning with AES 256-bit encryption
    How to securely connect a LAN POS to a remote point-of-sale device

    Network Intrusion Detection (IDS)
    Preventing SQL injection attacks: A network admin's perspective
    Lifecycle of a network security vulnerability
    Best Intrusion Prevention and Detection Products
    Rogue AP containment methods
    SIMs tools and tactics for business intelligence
    IPS and IDS deployment strategies
    Know when you need IDS, IPS or both
    Trend Micro to acquire Third Brigade for virtualization, cloud security
    New product aims to control rogue applications that avoid firewalls
    How to perform a network forensic analysis and investigation
    Network Intrusion Detection (IDS) Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    computer forensics  (SearchSecurity.com)
    Diffie-Hellman key exchange  (SearchSecurity.com)
    Einstein  (SearchSecurity.com)
    HIDS/NIDS  (SearchSecurity.com)
    network behavior analysis  (SearchSecurity.com)
    ultrasound  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts