The paper "State-Based Network Intrusion Detection System" is a good example of a finance and accounting assignment. Conventionally, to secure computer systems, programmers resorted to the creation of a protective “ shield” – so to speak – around these systems by way of design security mechanisms such as firewalls (see Lodin & Schuba), authentication mechanisms, Virtual Private Networks (VPN). However, these security mechanisms almost have inevitable vulnerabilities and they are usually not sufficient to ensure complete security of the infrastructure and to ward off attacks that are continually being adapted to exploit the system’ s weaknesses often caused by careless design and implementation flaws.

This accounts for the need for security technology that can monitor systems and identify computer attacks. This is called intrusion detection and is complementing conventional security mechanisms (Kumar, Srivastava & Lazarevic, 20).   To better understand Network Intrusion Detection System (NIDS), we first need to clarify its element terminologies. Firstly, an intrusion is an attempt to break into or misuse one’ s system. An intruder is more commonly known as a hacker – a generic term for a person who likes getting into things, with a benign hacker who likes to get into his/her own computer and understands how it works and a malicious hacker who likes getting into other people’ s systems -- or cracker (a term that benign hackers would like to be applied to them).

Now, intruders may be outsiders. That is, they may attack your network from outside – e.g. , defacing the web servers, forwarding spasm through e-mail servers, etc. – or may try to skirt around the security mechanisms used – such as firewalls -- to assail machines on the internal network.

Intruders from the outside (of the network) may proceed from the dial-up Internet lines, or maybe a result of physical break-ins, and/or maybe by one’ s partner (vendor, customer, reseller, etc. ) network that is linked to one’ s corporate network. Intruders may likewise be internal – i.e. , intruders that may legitimately use one’ s internal network, including users who misuse privileges (for example, an election officer who marked someone in the list of the voters as being dead for a political reason) or who impersonate higher privileged users (by using someone else’ s terminal).



