Security Monitoring Tools and Techniques
Monitoring security events is important because it helps detect and respond to potential threats in real time, preventing or minimizing damage by identifying suspicious activities before they can cause harm. Two important monitoring tools are intrusion detection systems (IDSs) and intrusion prevention systems (IPSs). IDSs only monitor, record, and provide alarms about intrusion activity, whereas IPSs also prevent intrusion activities.
Both tools are discussed in detail next.
IDS
An IDS is a security tool that monitors network traffic or system activities for signs of malicious activity or policy violations.
Components of an IDS
The following table shows the various components of an IDS:
Components |
Description |
Sensors |
The function of the sensors is to collect the data. Data can be in the form of... |