Internet / Network Security

  1. Home
  2. Computing & Technology
  3. Internet / Network Security

In Depth Security

The Demilitarized Zone (DMZ)

From Tony Bradley, CISSP. MCSE2k, MCSA, A+, for About.com

Should someone or something manage to get past the firewall, the next line of defense would be your IDS, or intrusion detection system. There are a few different ways of achieving intrusion detection. One of the more popular is through signature matching. Essentially, each time a new threat or exploit is learned a signature is created for it. The IDS monitors all traffic on the local network and looks for patterns that match the signatures it contains. Depending on the IDS you can configure it to counter the attack, halt the flow of traffic, alert the administrator or some other form of intervention or notification.

If the malicious code makes it past the firewall and past the IDS to your local computer, it would be left up to the anti-virus software to detect it and protect your system. Typical anti-virus software works in a similar manner to the IDS signatures. Each time a new virus is discovered its characteristics (subject line, message body, name of attached file(s), size of email or attached file(s)- anything that makes it unique and that is consistent) are catalogued and added to the list of known viruses. The software scans the local computer files, incoming emails and Internet traffic for signs of malicious code. While hacking and viruses are two different attacks that may occur on your system, many anti-virus software packages are set up to detect or prevent known security attacks, backdoors and Trojan horse programs that might be placed on your computer by a hacker.

These are just a small sampling of the layers available to defend your network. For more complicated or larger networks it is prudent to set up multiple firewalls and create a DMZ (demilitarized zone) to segment certain types of traffic that may need less restricted access to the public Internet from your internal systems. No matter how you choose to protect your network, it is important not to put all of your eggs in one basket, or to buy all of your eggs from the same chicken.

Explore Internet / Network Security

More from About.com

Internet / Network Security

  1. Home
  2. Computing & Technology
  3. Internet / Network Security

©2008 About.com, a part of The New York Times Company.

All rights reserved.