IDS | IPS | |
Placement | Out-of-band or not in the direct lines of communication | In-band or in the direct pathway of communication |
System type | Passive (monitoring and notify) | Active (monitoring and ability to take action) |
Detection mechanisms |
Signature detection Exploit facing |
Statistical anomaly-based detection Signature detection Exploit facing or vulnerability facing |
Keep in mind that an IDS listens and reports, but does not take any action, while the IPS listens and takes action if criteria is met.