Security Monitoring Tools and Techniques
Monitoring security events is a very important aspect of information security. Two important monitoring tools are Intrusion Detection Systems (IDSs) and Intrusion Prevention Systems (IPSs). IDSs only monitor, record, and provide alarms about intrusion activity, whereas IPSs also prevent intrusion activities.
Each of them is discussed in detail.
IDS
An IDS monitors a network (a network-based IDS) or a single system (a host-based IDS) with the aim of recognizing and detecting an intrusion activity.
Network-Based and Host-Based IDSs
The following table differentiates between network-based and host-based IDSs:
Network-based IDS |
Host-based IDS |
It monitors activities across the network |
It monitors the activities of a single system or host |
Comparatively, network-based... |