- how does the intruder enter the system?
- why can the intruder invade the system?
- how does the intruder obtain the password?
- model invasion process?
- which does the general invasion type have?
- what is crack (exploits)?
- anything is reconnoiters (reconnaisance) [to translate the note: The original text so, doubts is reconnaissance?]
- what is refuses to serve (DoS)?
- present's attack has the multi-dangers?
- where can find now the aggressive behavior statistics?
2. construction
- how invades to examine?
- How does NIDS distinguish the inflow data?
- what after examining attacks, NIDS is done?
- what similar measure also has except NIDS?
- what place should I install NIDS in network?
- how to let IDS suit the security construction other parts?
- how to examine whether to move IDS?
3. countermeasure
- how to enhance under WinNT the invasion examination and the prevention?
- how to enhance under Win95/98 the invasion examination and the prevention?
- how to enhance under Unix the invasion examination and the prevention?
- how to enhance under Macintosh the invasion examination and the prevention?
- how to enhance enterprise's invasion examination and the prevention?
- how to realize the invasion examination in the enterprise?
- after attacking, I should make what?
- some people said that they are attacked from my here, how should I do?
- how to collect enough many about intruder's evidence?
4. product
- which free software (freeware) has or the shareware (shareware) invasion examination system?
- which commercial invasion examination system has?
- what is " the network search " (network grep) the system?
- what tool does the intruder use to enter my system?
- I should care other invasion examination system?
6. resources
- where can discover the new system crack's renewal?
- other related securities and invasion examination resources?
- has stand which are noteworthy?
7.IDS and firewall (firewall)
- why had the firewall also to need IDS?
- had the invasion examination, but also needs the firewall?
- Does IDS obtain the information from where? Firewall?
8. realizes the guide
- which questions should I ask IDS provider?
- how I in do continue (on-going) in the foundation to maintain the system?
- how do I stop not the suitable network browsing?
- how do I establish my IDS (to write code)?
- NIDS is legitimate (, since this is one kind of interception)?
- how to protect the journal file not to tamper with the evidence?
9.NIDS limitation
- exchange network (inherent limitation)
- resources limitation
- NIDS attack
- simple reason
- complex reason
pneumatic tool
10. miscellaneous
- which standard/interoperability endeavor
11. honey jar and deceit system
- what is an honey jar?
- which merits does the honey jar have?
- which does the honey jar have disadvantageously?
- how to establish my honey jar?
- which types does the honey jar have?
- establishes one to be possible system's positive reaction which attacks?