Monitoring security events is a very important aspect of information security. Two important monitoring tools are Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS). IDS only monitor, record, and provide alarms about intrusion activity, whereas IPS also prevent intrusion activities.
Let's study each of them in detail.
Intrusion detection system
An IDS helps to monitor a network (network-based IDS) or a single system (host-based IDS) with the aim of recognizing and detecting an intrusion activity.
Network-based and host-based IDS
The following table differentiates between network-based and host-based IDS:
Network-based IDS | Host-based IDS |
It monitors activities across the network | It monitors the activities of a single system or host. |
Comparatively, network-based IDS have high false positives (in other words, a high rate of false alarms) | Host-based IDS have low false positives (in other words, a low rate of false... |