ABSTRACT

It is important to know the main stages of an intrusion, so that they can be detected at an early phase, and to overcome them before they can cause any damage. Typically an intrusion goes through alert phases from yellow, which shows some signs of a potential threat, to red, which involves the potential stealing of data or some form of abuse. The main phases are defined in Figure 8.1.