Working with IPS/IDS
In this section, we will explain what an IDS and an IPS are, provide some examples of these systems, and also consider the differences between these two similar technologies.
What is an IDS?
An IDS is a passive monitoring solution that detects unwanted intrusions in our networks.
Once the intrusion is detected, the IDS will send an alert to a security analyst for further investigation and action (as shown in the following figure):
In terms of deployment, an IDS can be deployed at the host level (HIDS) or network level (NIDS).
There are two main IDS engines, one that is based on signatures (examples are classic antiviruses that use a database of signature to detect malicious software), and one that is anomaly-based, which detects intrusions based on deviations from established patterns. In this latter category, there are also systems that leverage cognitive computing to enhance the recognition...