Govur University Logo
--> --> --> -->
...

A very clever bad guy hides inside a computer system for a long, long time without being seen. What two main security tools, one watching all the network roads and another watching what each single computer is doing, must work together to find and stop this hidden bad guy?



To find and stop a hidden bad guy who has been inside a computer system for a long time, two main security tools must work together: a network intrusion detection system (NIDS) and a host-based intrusion detection system (HIDS). The NIDS watches all the network roads, which means it inspects all the data traffic flowing in and out of the computer system across its network connections. Think of it like a security guard at the main entrance of a building, checking everyone and everything that comes and goes. The NIDS looks for suspicious patterns in this traffic, like unusual connection attempts, data exfiltration (data being stolen and sent out), or co....

Log in to view the answer



Community Answers

Sign in to open profiles and full community answers.

Ali Raza Afzal

“To findand stop a hidden bad guy who has been inside a computer system for a long time, two main security tools must work to gether: anetwork itrusion detection system (NIDS) and a host - based intrusion detection system (HIDS). The NIDS looks for suspiciouse patterns in this traffic , like unusual connection attempts, data exfiltration (data being stolen and sent out ),or communication with known maliciouse servers. It operates by analyzing network packets, which are small chunks of data that travel across the net work, and comparing them against a database of known attack signatures or against normal network behavior to spot anomalies. The HIDS ,on the other hand, watches what each single computer is doing. This is like having security cameras inside each room of the building ,monitoring the activity within. The hids is installed on individual computers (called hosts) and monitors their internal activities. This includes looking at system logs(records of events on the computer),file integrity ( checking if important system files have been modified), running processes ( what programs are currently active),and user activity. the hids can alert the nids to suspiciouse activity within . the hids can detect maliciouse activities that might not be visible from the network perspective, such as malware that has already infected a system and is operating internally. when these two systems work together, the nids can alert the hids to potential threats originating from the network, and hids can confirm if those threats are actually manifesting on specific computers . conversely ,the hids can alerts the nidsto suspiciouse activity on the host that might indicate an ongoing attack the nids has not yet fully identified . this coordinated effort creates a comprehensive security posture, allowing for the early detection and effective stopping of persistent, hidden thr”

100.0%

Ismail Mahbuub

“the two main security tools that must work together to find a hidden bad guy are : 1. Network intrusion detection system ( DIDS) : these tool watches all the network roads by inspecting all the data traffic flowing in and out of the computer system across its network connections ( like a security guard at a building's main entrance). it analyzes network packates and compares them against known attack signatures or normal behavior to spot anomalies, such as usual connection attempts, data exfiltration, or communication with malicious servers. 2. Host based instrusion detection system ( HIDS) : these tool watches what each single computer is doing by being installed directly on individual computers ( hosts) to monitor internal activities ( like security cameras inside each room) it looks at system logs, file integrity, running process, and user activities to detect internal malicious actions and malware that may not be visible from a network perspective. how they work together : the NIDS alerts the HIDS to potential threat originating from the network, while the HIDS confirms if those threats are manifesting on specific computers or alerts the NIDS to suspicious host activity. By correlating network -level suspicious events with host-level suspicious activities, they creat a coordinated, comprehensive security posture to catch presistent, hidden threats.”

100.0%

Elvin Shirazov

“The two main security tools that must work together to find a hidden bad guy are: Network Instrusion Detection System (NIDS): This tool watches all network roads by inspecting all data traffic flowing in and out of the computer systems accross its network connections (like a security guard at a building's main entrance). It analyzes network packets and compares them against known attack signatures or normal behavior to spot anomalies, such as unusual connection attempts, data exfiltration, or communication with malicious servers. Host-based Instrusion Detection System (HIDS): This tool watches what each single computer is doing by being installed directly on individiual hosts to monitor internal activities (like security cameras inside each room). It looks at system logs, file integrity, running processes, and user activities to detect internal malicious actions and malware that may not be visible from a network perspective. How they work together: The NIDS alerts the HIDS to potential threats orginating from the network, while the HIDS confirms if those thrats are manifesting on specific computers or alerts the NIDS to suspicous activities. Together, they create a coordinated, comprehensive security posture to catch persistent, hidden threats.”

100.0%

Siddhi Mishra

“two main security tools must work together : A. network intrusion detection system and B. host-based intrusion detection system NIDS: it watches all the network roads, which means it inspecta all the data trafffic flowing in and out of the system across it's network connections. It is like security gaurd at the main entrance of a building . NIDS looks for suspicious pattern in traffic like unusual connection attempts, data exfiltration and communication with known malicious servers. also analyze network packets travel across network . HIDS: it watches each single computer what it's doing like the security cameras inside the room . it can detect malicious activites which are invisible when these two system work together , the nids can alart the hids to potential threats originating from the network, hids confirms if those threats are actully manifestinf on specific system hids can alert the nids to suspicious activity on a host that might indicate an ongoing attack that nids has not fully identified”

100.0%

Hunter Saenz

“The two main security tools that must work together to find a hidden bad gue are 1. Network intrusion detection system (DIDS) these tools watches all the network roads by inspecting all the data traffic flowing in and out of the computer system across its network connections (like a security guard at a building's main entrance). It analyzes network packates and compares them against knwon attack signatures or normal behavior to spot anomalies, such as usual connection attempts, data exfiltration, or communciation with malcious servers/. 2. Host based intrustions detection system (HIDS) these tools watch what each single computer is doing by being installed directly on individual computers (hosts) to monitor internal activites ( like security cameras inside each room) it looks at system logs, file integrity, running process, and user activities to detect internal malicious actions and maleware that may not be visible from a network perspective. How they work together the NIDS alerts the HIDS to potential threat orginating from the network, while the HIDS confirms if those threats are manifesting on specfic computers or alerts the NIDS to suspicious host activities, they create a coordinated, comprehensive security posture to catch persistent, hidden thrreats.”

100.0%

Rohan Adhikari

“To find and stop a hidden bad guy who has been inside a computer system for a long time, two main security tools must work together: a network intrusion detection system (NIDS) and a host-based intrusion detection system (HIDS). The NIDS watches all the network roads, which means it inspects all the data traffic flowing in and out of the computer system across its network connections. Think of it like a security guard at the main entrance of a building, checking everyone and everything that comes and goes. The NIDS looks for suspicious patterns in this traffic, like unusual connection attempts, data exfiltration (data being stolen and sent out), or communication with known malicious servers. It operates by analyzing against normal network behavior to spot anomalies. The HIDS, on the other hand, watches what each single computer is doing. This is like having security cameras inside each room of the building, monitoring the activity within. The HIDS is installed on individual computers (called hosts) and monitors their internal activities. This includes looking at system logs (records of events on the computer), file integrity (checking if important system files have been modified), running processes (what programs are currently active), and user activity. The HIDS can detct malicious activities that might not be visible from the network perspective, such as malware that has already infected a system and is operating internally. When these two systems work together, the NIDS can alert the HIDS to potential threat originating from the network, and the HIDS can confirm if those threat are actually manifesting on specific computers. Conversely, the HIDS can alert the NIDS to suspicious activity on a host that might indicate an ongoing attack the NIDS has not yet fully identified. This coordinated effort creates a comprehensive security posture, allowing for the early detection and effective stopping of persistent, hidden threats by correlating network-level suspicious events with host-level suspicious activities.”

94.0%

Layba Hamid Khan

“1. Network Detection and Response (NDR): An NDR solution continuously monitors network traffic - the data flowing between devices, servers, and cloud environments - to detect suspicious or malicious activities, NDR uses techniques such as traffic analysis, behavioural analytics, and threat intelligence to identify attacks like command-and-control (C2) communication, lateral movement, data exfiltration, and other unusual network behaviours that may indicate a hidden attacker operating within the network. BY providing visibility inot all netwrok communications, NDR helps security teams detect threats that traditional security tools may miss. 2. Endpoint Detection and Response (EDR): An EDR solution continuously mmonitors endpoints such as computers, laptops, and servers for suspicious activities like malware, unauthori”

94.0%

Isabelle Chen

“To find and stop a hidden bad guy who has been inside a computer system for a long time, two main security tools must work together: a network intrusion detection system (NIDS) and a host-based intrusion detection system (HIDS). The NIDS watches all the network roads, which means it inspects all the data traffic flowing in and out of the computer system across its network connections. Think of it like a security guard at the main entrance of a building, checking everyone and everything that comes and goes. The NIDS looks for suspicious patterns in this traffic, like unusual connection attempts, data exfiltration (data being stolen and sent out), or communication with known malicious servers. It operates by analyzing network packets, which are small chunks of data that travel across the network, and comparing them against a database of known attack signatures or against normal network behavior to spot anomalies. The HIDS, on the other hand, watches what each single computer is doing. This is like having security cameras inside each room of the building, monitoring the activity within. The HIDS is installed on individual computers (called hosts) and monitors their internal activities. This includes looking at system logs (records of events on the computer), file integrity (checking if important system files have been modified), running processes (what programs are currently active), and user activity. The HIDS can detect malicious activities that might not be visible from the network perspective, such as malware that has already infected a system and is operating internally. When these two systems work together, the NIDS can alert the HIDS to potential threats originating from the network, and the HIDS can confirm if those threats are actually manifesting on specific computers. Conversely, the HIDS can alert the NIDS to suspicious activity on a host that might indicate an ongoing attack the NIDS has not yet fully identified. This coordinated effort creates a comprehensive security posture, allowing for the early detection and effective stopping of persistent, hidden threats by correlating network-level suspicious events with host-level suspicious activities.”

91.0%

Celia Aitseddik

“to detect and stop a sophisticated attacker who maintains a long-term presence within an environment Network Detection and Response NDR and Endpoint Detection and Response EDR should work together , NDR continuously monitors network traffic and communications to identify suspicios bhaviour such as command and control activity lateral movemenet and data exfiltration while EDR monitors individual endpoints for malicious processes persistence mechanisms privilege escalationand other host level indicators of compromise by correlating network level from NDR with endpoint level activity from EDR security tam can establish a broader attack timeline detect stealthy threats that may evade either control independently and rapidly contain compromised systems”

86.0%

Alok Verma

“To find and stop a hidden bad guy who has been inside a computer system for a long time, two main security tools must work together. a network intrusion detection system (NIDS) and a host -based intrusion detection system (HIDS). the NIDS watches all the network roads, which means it inspects all the data traffic flowing in and out of the computer system across its network connection. the HIDS, on the other hand, watches what each single computer is doing. this is like having security cameras inside each room of the building, monitoring the activity within. the HIDS is installed on individual computer and monitors their internal activities. conversely, the HIDS can alert the NIDS to suspicious activity on a host that might indicate an ongoing attack the NIDS has not yet fully identified. this coordination effort creates a comprehensive security posture, allowing for the early detection and effective stopping of persistent, hidden threats by correlationg network-level suspicious events with host-level suspicious actiities.”

83.0%

Senewirathna Amith Nilupul

“To find and stop a hidden bad guy who has been inside a computer system for a long time, two main security tools must work together: a network intrusion detection system (NIDS) and host -based intrusion detection system (HIDS). The nIDS watches all the network roads, which means it inspects all the data traffic flowing in and out of the computer system across its network connections. Think of it like a security guard at the main entrance of a building, checking everyone and everything that comes and goes. The NIDS looks for suspicious patterns in this traffic, like unusual connection attempts, data exfiltration (data being stolen and sent out), or communication with known malicious servers. It operates by analyzing network packets, which are small chunks of data that travel across the network, and comparing them against a database of known attack ignatures or against normal network behavior to spot anomalies.”

82.0%

Mohammad Muzzammil Khan

“To find and stop a hidden pesistent threat, security teams must deploy a Network Intrusion Detection System (NIDS) and a Host-based Intrusion Detection System (HIDS) in tandem. The NIDS watcheas all network roads by inspectiong incoming and outgoing traffic packets to stop anomalies like usual connection attempts ,data exfilteration, or known attack signatures. Concurrently, the HIDS monitors individual computer hosts from the inside, auditing internal activities such as logs, active running processes, and file integrity checking. Working together this dual-layered approach ensures that both network-wide traffic anomalies and unauthorised local system behaviorsare caught to eliminate the hidden adversary.”

81.0%

Mostafa Mahmoud Khatab Tarad

“to detect and stop a long term hidden attacker , the security team should use NIDS and HIDS togather NIDS monitors network traffic and packets to detect suspicious connections ,known attack signatures , abnormal communications and possible data exfiltration. HIDS monitors activity inside individual hosts , including system logs ,file integrity , running processes and user activity . by correlating network level alerts from NIDS with host level evidence from HIDS the security team gains better visibility ,confirms wherher suspicious network activity has affected a host and can detect persistent threats that either tool might miss alone.togather they provide layered detection and faster incident response”

80.0%

Malikejder

“The two security tools are a Network Intrusion Detection System (NIDS) and a Host Intrusion Detection System (HIDS). A NIDS monitors network traffic to detect suspicious connections, malicious communications, lateral movement, and data exfiltration attempts across the network. A HIDS monitors individual hosts by analyzing, system logs, file integrity, running processes, user activity, and other endpoint events. Working together, the NIDS identifies network-based threats while the HIDS confirms malicious activity on the affected hosts. By correlating network-level and host-level events, they provide comprehensive visibility and enable the rapid detection and containment of persistent, hidden attackers.”

80.0%

Nikulkumar Suthar

“the two security tools are , Network intrusion detection system is monitor all network traffic to detect suspicious activities such as unauthorised access, malicious connections, dara exfiltration, and communocation with known malicious server by analysing network packets. Host Based intrusion detection system is monitored individual computer by checking system logs, file integrity, running processes, and user activity to detact malware or other malicious actions occurring on the system. Thogether NIDS and HIDS provide comprehensive security by correlating network level events with host level activities, enabling the detection and prevention of long term hidden attack”

77.0%

Mohamed Malek Toumi

“To detect and stop a hidden attacker, security teams use both Network-based Intrusion Detection Systems (NIDS) and Host-based Intrusion Detection System (HIDS). NIDS monitors network traffic to detect suspicious communications, attack patterns, or data exfiltration. HIDS monitors individual hosts by analyzing system logs, file changes, processes, and user activity. By working together, NIDS provides visibility into network-level threats while HIDS detects suspicious activity occurring directly on systems, providing more complete threat detection.”

62.0%

Umamaheswara Rao K

“The two main security tools are: 1. Network detection and response(NDR): watches all the network roads- meaning it monitors network traffic for unusual or suspicious activity. 2. Endpoint detection and response(EDR): watches what each individual computer is doing- it tracks processes, file changes, user actions and more. Examples: NDR: -darktrace -Vectra AI -Cisco secure network analytics EDR: -crowdstrike falcon -microsoft defender for endpoint -sentinelone together, they give the security team a full picture, amking it much harder for attackers to hide.”

62.0%

Ghofrane Horchani

“a clever attcker who stays hidden inside a system for a long time can be detected using two main security tools; NDR (network detection and response) and EDR(endpoint detection and response). NDR MONITORS network traffic to identify suspicious communications and abnormal activities across the network, while EDR monitors individual computers(endpoint) to detect malicious process, file changes, and unusual behavior. by working together, NDR et EDR provide better visibility and help security teams detect and stop advanced hidden threats.”

61.0%

Mishaal Anwar

“To find a hidden attacker, NDR and EDR must work together. NDR acts like a traffic camera watching all the 'network roads' to spot unusual communication or data moving between systems, while EDR acts like a security guard on each individual computer, monitoring files and active processes for malicious behavior By combining forces (a strategy known as XDR), these tools allow security teams to peece together the attacker's full path - cath9n them whether they are traveling acroess the newteok or hiding deep insider a single”

59.0%

Shan Devinda

“To detect a steathy, long dwelling attacker like: security teams rely on NDR, which monitors all the network traffic and communication paths for unusual patterns or hidden malicios activity, working together with EDR, which watches the behavior of each individual computer or device for suspicious process files or actions combining both gives visibility across the network and on the endpoints, making it much harder for the intruder to stay hidden.”

51.0%

Anmol Singh Chhetri

“The two tools are a network intrusion detection system (NIDS) and a host-based intrusion detection system (HIDS). The NIDS monitors all network traffic for suspicious activity, while the HIDS monitors the internal activity of each individual computer (logs, file changes and processes). By working together and correlating network-level and host-level alerts, they can detect and stop a hidden attacker who has persisted inside the system for a long time.”

48.0%

Mustafa Fathi

“A NIDS and a HIDS work together to detect and stop a long-term hidden attacker. The NIDS monitors network traffic for suspicious communications, while the HIDS monitors activities on individual hosts, such as system logs, file Integrity, processes, and user actions. By correlating network events with host activity, they can detect persistent threats that either system alone might miss.”

44.0%

Lahiru

“The two main security tools are a Network Intrusion detection system and a hot intrusion detection system. A NIDS monitor network traffic for suspious activity while a HIDS watches the file, process and or individual computer, YTogether, they help detect and stop attackers who stay hidden in a system for a long time by monitoring both the network and the host.”

41.0%

Md. Sheikh Farid

“For detecting a long term hidden attacker, Network Detection and Response (NDR) and Endpoint Detection & Response (EDR) must work together. NDR watches network traffic for suspicious communication, while EDR monitors activity on individual computers. Together, they can detect hidden attacks, trace the attacker's activity and help stop the threat.”

39.0%

Dong Xu

“The two main tools are NDR network detection and response and EDR endpoint detection and response. NDR monitors network traffic for suspicious activity, while EDR monitors individual computers and devices. Together, they help detect and stop advanced persistent threats that may remain hidden for a long time.”

35.0%

Jaire Carthens

“network intrusion detection system and host based intrusion detection system are the two tools that are being used they both provide a network wide amd host level view of securoty events, by correlating alerrts from both systems while stoppinh long term hidden threats such as APT's”

32.0%

Flávio Andrade

“The two tools are NDR (Network Detection and Response) and EDR (Endpoint Detection and Response). NDR provides network traffic and communication clues, while EDR provides endpoint activity and process-behavior clues. Together, they help detect and stop hidden attackers.”

30.0%

Gayatri Sudhakar Hire

“The two tools are network intrusion detection system and host based intrusion detection system . nids inspects traffic across the network, while HIDS monitors activity inside attackers by combining network- level suspicious event with host- level suspicious activities.”

30.0%

Saophirun Chem

“Network security solution such as TrendAI deep discovery for inspect the traffic incoming and outgoing of the organization. For endpoint server or pc we can using with XDR solution to protect and investigate and threat hunting inside the network enviornment.”

27.0%

E Yaswanth Naik

“NDR watches all network traffic to catches c2 beaconing lateral movement, and data exfiltration between machines. EDR watches e ach individual compuetr to catch suspicious process,persistence mechanisms and malicious file activity”

26.0%

Rida Nadeem

“NIDS watches the network, HIDS waches host , toether they can work and helo to detect a long term hidden attacker like APTadvanced persisitent threat by combining network level and host level evidence”

22.0%

Sudarshan Lamichhane

“The two security tools are Network intrusion Detection System (NIDS), which monitors network traffic, and Host-based intrusion detection system (HIDS), which monitors activities on individual computer. Together, they detect and stop hidden attackers.”

21.0%

Ahmed Nabeel Alobaidi

“the catch a hidden threat these two tools must work together: NIDS/NIPS: watches all network trafic or malicious patterns EDR: monitors individual computer activity or suspicious begavior”

19.0%

Suat Aliu

“NDIS (network detection intrusion system) and EDR/HIDS (endpoint detection and response/host intrusion detection system)”

13.0%

Muhammad Mudassar

“the two main security tools required to solve this riddle are NIDS ( network intrusion detection system ) and HIDS ( host intrusion detection system)”

11.0%

Adewale Ibrahim

“Network Intrusion Detection System - NIDS and Host-Based Intrusion Detection System - HIDS”

7.000000000000001%

Muhammad Aamir Riaz

“network intrusion detection system (NIDS) and a host-based intrusion detection system (hids)”

7.000000000000001%

Arunank

“NIDS(Network Intrusion Detection System) and HIDS(Host Intrusion Detection System)”

6.0%

Manav Vithalani

“Network Intrusion Detection System (NIDS) and Host Intrusion Detection System (HIDS)”

6.0%

Lucky Samuel

“Network intrusion detection system and Host based intrusion detection system”

5.0%

Samuel Kalu

“chain of custody”

1.0%

Kabo Sekoto

“NIDS AND HIDS”

1.0%

Hasinee Mirtipati

“NIDS, HIDS”

1.0%

Md Yousuf Ali

“EDR, NDR”

0.0%

GĂĽven Ada

“None”

0.0%

Kattunga Kumar Soma Sekhar

“None”

0.0%

Anirban Ghosh

“NDR and EDR”

0.0%

Victor Samuel Da Paixao

“NDR and EDR.”

0.0%

David Neves De Oliveira

“caça viçoes escondidos”

0.0%

Gazi Muhammad Abdullah Mahfuz

“123”

0.0%

Idrisa Haruni Kigaile

“None”

0.0%

Redundant Elements