3 ms·
To learn about Intrusion Detection Systems (IDS) I found Unifi's documentation quite helpful. It's specific for their product but most of it is applicable elsew
by sqren 6y ago
To learn about Intrusion Detection Systems (IDS) I found Unifi's documentation quite helpful. It's specific for their product but most of it is applicable elsewhere.
https://help.ui.com/hc/en-us/articles/360006893234-UniFi-USG-UDM-Configuring-Internet-Security-Settings https://help.ui.com/hc/en-us/articles/360006893234-UniFi-USG...
> What are some common rules that get applied?
This is specifically answered under "Categories and Their Definitions":
> Compromised: This is a list of known compromised hosts, confirmed and updated daily as well.
> Scan: Things to detect reconnaissance and probing. Nessus, Nikto, portscanning, etc. Early warning stuff.
> SpamHaus: This ruleset takes a daily list of known spammers and spam networks as researched by Spamhaus.
> Web Apps: Rules for very specific web applications.
- crispyambulance 6y agoOK, thanks! so it can be like a firewall except dynamically updated by subscribing to some kind of service? This would work even for encrypted traffic.