What is an IPS?
IPS started as Intrusion Detection Systems in the 1990s. The most commonly used IDS/IPS product from the beginning (way back in the 1990s) was Snort, which is still a product (both open source and commercial), and which many other modern IPS products are now based on.
An IPS watches network traffic for known attacks and then blocks them. Of course, there are a few failings in this process:
- Enumerating badness is a solid losing proposition, which the anti-virus industry has long realized. No matter what signature pattern you enumerate for, an attacker can mount the same attack with only minor modifications to evade signature-based detections.
- False positives are a milestone around the neck of these products. If they're not configured properly, it can be easy for a signature to mistakenly flag normal traffic as malicious and block it.
- At the other end of the spectrum, if the configuration is too permissive, it can be easy to not alert or block...