Home > Ask the Security Experts > Network Security Questions & Answers > Intrusion detection vs. intrusion prevention
Ask The Security Expert: Questions & Answers
EMAIL THIS

Intrusion detection vs. intrusion prevention

Mike Chapple, featured expert EXPERT RESPONSE FROM: Mike Chapple, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 May 2008
What are the similarities and the differences between an IDS and an IPS? Can they be used to perform the same functions in a network?


BROWSE BY TAG
Network Security,   Network Intrusion Detection (IDS),   Network Intrusion Detection and Analysis,   Enterprise Network Security,   Network Intrusion Prevention (IPS),   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Security
Should enterprises be running multiple firewalls?
What are best practices for fiber optic cable security?
What are the disadvantages of proxy-based firewalls?
What is the difference between a VPN and remote control?
What are the best practices for IPS implementation?
How to prevent DDoS attacks on websites
How to configure firewall ports for webmail system implementation
How should service providers address VoIP security issues and threats?
Can S/MIME, XML and IPsec operate in one protocol layer?
How to set up a corporate cell phone management strategy

Network Intrusion Detection (IDS)
SIMs tools and tactics for business intelligence
IPS and IDS deployment strategies
Know when you need IDS, IPS or both
Trend Micro to acquire Third Brigade for virtualization, cloud security
New product aims to control rogue applications that avoid firewalls
How to perform a network forensic analysis and investigation
What is the cause of an 'intrusion attempt' message?
Host-based intrusion prevention addresses server, desktop security
Product review: AirDefense Enterprise 7.3
Best practices for IDS creation and signature database maintenance
Network Intrusion Detection (IDS) Research

Network Intrusion Prevention (IPS)
Lesson 1 quiz: Risky business
Hacker attack techniques and tactics: Understanding hacking strategies
SIMs tools and tactics for business intelligence
IPS and IDS deployment strategies
Know when you need IDS, IPS or both
Trend Micro to acquire Third Brigade for virtualization, cloud security
What are the best practices for IPS implementation?
Host-based intrusion prevention addresses server, desktop security
IBM announcements mark two years of ISS marriage
Product review: AirDefense Enterprise 7.3
Network Intrusion Prevention (IPS) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
computer forensics  (SearchSecurity.com)
Diffie-Hellman key exchange  (SearchSecurity.com)
Einstein  (SearchSecurity.com)
HIDS/NIDS  (SearchSecurity.com)
network behavior analysis  (SearchSecurity.com)
ultrasound  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Actually, intrusion detection systems and intrusion prevention systems are quite similar in technology, but they perform slightly different functions on the network.

Both IPS and IDS tools are designed to monitor network activity for signs of misuse. There are two basic strategies that they may follow to identify potentially malicious traffic:

  • Signature detection systems have databases containing patterns of known malicious activity, similar to those used by antivirus software. They watch all network traffic for any communications that match those patterns and, if they see any matches, trigger an alert.
  • Anomaly-detection systems monitor the network and build models of normal behavior over a period of time known as the "training period." They then watch the network for activity that deviates from those standards. If the deviation is significant, the anomaly-detection system triggers an alert.

The difference between IPS and IDS systems comes in their handling of alerts. Pure IDS systems simply inform the administrator that suspicious activity took place. IPS systems, on the other hand, have the ability to block the suspicious traffic from entering the network. In fact, the two technologies have already converged for all intents and purposes. Most intrusion detection products have the ability to run in either IPS or IDS mode depending upon the user's configuration.

More information:

  • There's a good debate taking place right now in the security industry about the proper balance between IPS and IDS in the enterprise. For more, read Network intrusion prevention systems: Should enterprises deploy now?
  • Get the latest news on intrusion detection and intrusion prevention.




  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts