Security Architecture and Engineering

Reconnaissance

Reconnaissance is a mission to obtain information by visual observation or other detection methods, about the activities and resources of an enemy or potential enemy, or about the meteorologic, hydrographic, or geographic characteristics of a particular area

  • Many attack techniques depend on reconnaisance.
  • The attacker has to know the weak points.
  • Blocking, or at least spotting, reconnaisance is a major defense.

Blocking Reconnaissance

Intrusion detection systems can spot probes: get notified when possible probing activity is detected.

Sophisticated variant: low, slow, distributed reconnaissance — probe from multiple points.