Intrusion detection and prevention systems
The purpose of firewalls is to allow legitimate traffic and block malicious traffic. However, an intrusion system is required in the event that malicious traffic is not blocked by the firewalls. There are two forms of intrusion systems:
- Intrusion Detection System (IDS): An IDS detects potential malicious traffic but doesn’t block the traffic. Whenever an IDS detects malicious traffic, it sends an alert to the respective teams to investigate the alert. Therefore, it’s critical to fine-tune the IDS rules for appropriate thresholds so those teams don’t get slammed with thousands of false positive alerts. IDSs are passive systems and only observe the network traffic, hence they do not have any effect on the network throughput.
- Intrusion Prevention System (IPS): An IPS detects and blocks malicious traffic. An IPS is required to be implemented in the line of traffic so it can prevent traffic from entering the network...