Home > Ask the Security Experts > Network Security Questions & Answers > Intrusion detection vs. intrusion prevention
Ask The Security Expert: Questions & Answers
EMAIL THIS

Intrusion detection vs. intrusion prevention

Mike Chapple, featured expert EXPERT RESPONSE FROM: Mike Chapple, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 May 2008
What are the similarities and the differences between an IDS and an IPS? Can they be used to perform the same functions in a network?


BROWSE BY TAG
Network Security,   Network Intrusion Detection (IDS),   Network Intrusion Detection and Analysis,   Enterprise Network Security,   Network Intrusion Prevention (IPS),   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network Security
How to set up a split-tunnel VPN in Windows Vista
What is the difference between static and dynamic network validation?
Port scan attack prevention best practices
Securing the intranet with remote access VPN security
How to prevent network sniffing and eavesdropping
How to implement virtual firewalls in a complex network infrastructure
How to manage network bandwidth with distributed ISP bandwidth
How to edit group policy objects to give a user local admin rights
How to prevent operating system cloning with AES 256-bit encryption
How to securely connect a LAN POS to a remote point-of-sale device

Network Intrusion Detection (IDS)
Preventing SQL injection attacks: A network admin's perspective
Lifecycle of a network security vulnerability
Best Intrusion Prevention and Detection Products
Rogue AP containment methods
SIMs tools and tactics for business intelligence
IPS and IDS deployment strategies
Know when you need IDS, IPS or both
Trend Micro to acquire Third Brigade for virtualization, cloud security
New product aims to control rogue applications that avoid firewalls
How to perform a network forensic analysis and investigation
Network Intrusion Detection (IDS) Research

Network Intrusion Prevention (IPS)
Aligning network security with business priorities
Best Intrusion Prevention and Detection Products
Port scan attack prevention best practices
Lesson 4: How to use wireless IPS
Lesson 1 quiz: Risky business
Hacker attack techniques and tactics: Understanding hacking strategies
SIMs tools and tactics for business intelligence
IPS and IDS deployment strategies
I'll be watching you: Wireless IPS
Know when you need IDS, IPS or both
Network Intrusion Prevention (IPS) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
computer forensics  (SearchSecurity.com)
Diffie-Hellman key exchange  (SearchSecurity.com)
Einstein  (SearchSecurity.com)
HIDS/NIDS  (SearchSecurity.com)
network behavior analysis  (SearchSecurity.com)
ultrasound  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Actually, intrusion detection systems and intrusion prevention systems are quite similar in technology, but they perform slightly different functions on the network.

Both IPS and IDS tools are designed to monitor network activity for signs of misuse. There are two basic strategies that they may follow to identify potentially malicious traffic:

  • Signature detection systems have databases containing patterns of known malicious activity, similar to those used by antivirus software. They watch all network traffic for any communications that match those patterns and, if they see any matches, trigger an alert.
  • Anomaly-detection systems monitor the network and build models of normal behavior over a period of time known as the "training period." They then watch the network for activity that deviates from those standards. If the deviation is significant, the anomaly-detection system triggers an alert.

The difference between IPS and IDS systems comes in their handling of alerts. Pure IDS systems simply inform the administrator that suspicious activity took place. IPS systems, on the other hand, have the ability to block the suspicious traffic from entering the network. In fact, the two technologies have already converged for all intents and purposes. Most intrusion detection products have the ability to run in either IPS or IDS mode depending upon the user's configuration.

More information:

  • There's a good debate taking place right now in the security industry about the proper balance between IPS and IDS in the enterprise. For more, read Network intrusion prevention systems: Should enterprises deploy now?
  • Get the latest news on intrusion detection and intrusion prevention.




  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts