1. What Is an “Intrusion,” Anyway?
Information security concerns itself with the confidentiality, integrity, and availability of
information systems and the information or data they contain and process. An intrusion, then,
is any action taken by an adversary that has a negative impact on the confidentiality,
integrity, or availability of that information.
Given such a broad definition of “intrusion,” it is instructive to examine a number of
commonly occurring classes of information system (IS) intrusions.