Intrusion Detection Systems and Intrusion Prevention Systems
Monitoring security events is a very important aspect of information security. Two important monitoring tools are Intrusion Detection Systems (IDSs) and Intrusion Prevention Systems (IPSs).
Intrusion Detection Systems
An IDS helps to monitor a network (network-based IDS) or a single system (host-based IDS) with the objective of recognizing and detecting intrusions.
Network-Based and Host-Based IDSs
The following table differentiates between network-based and host-based IDSs:
Network-based IDS |
Host-based IDS |
Monitors activity on the entire network |
Monitors activity of a single system or host |
Has high false positives (that is, high rates of false alarms) |
Has low false positives (that is, low rates of false alarms) |
...