Problem solve Get help with specific problems with your technologies, process and projects.

Can an IDS, DMZ and honeypot together achieve better network security?

An IDS and DMZ can be used together to achieve better network security, but expert Mike Chapple explains which tool is too risky to add to the mix.

How can an IDS, DMZ and honeypots work together to achieve better security?
Intrusion detection systems (IDS) and demilitarized zones (DMZ) play critical roles in the security of modern enterprises. I strongly recommend that anyone with Internet-facing systems implement both of these technologies to improve the security of their networks.

Your IDS provides you with visibility into activity on your network. It monitors network activity, seeking out...

suspicious actions that may represent attacks on your network. In IDS mode, the system alerts administrators to this suspicious activity for further investigation. It's also possible to put many systems into intrusion prevention system (IPS) mode, transforming the IDS from a passive device to one that plays an active role in your network security by blocking malicious activity from entering your network in the first place. For more on this topic, see the intrusion detection and prevention learning guide.

DMZs allow you to isolate systems that offer public services to Internet users in a single area of your network. You can then provide the DMZ with limited access to your internal network. The goal is to minimize the ability of an intruder to penetrate your internal network if he or she compromises an exposed system in the DMZ. For more information on implementing DMZs, see my Firewall Architecture Tutorial.

Finally, you also asked about honeypots in your question. Unlike the two other technologies you mentioned, I strongly discourage the use of honeypots unless you're conducting active security research and have a need to attract malicious activity to your network. As you may know, honeypots are systems that are designed to be compromised in an effort to attract hackers and malware so that they may be monitored in a controlled environment. This type of activity is extremely risky – if you misconfigure your honeypot, you may wind up with a true compromise on your hands!

More information:

This was last published in August 2008

Dig Deeper on Network intrusion detection and prevention (IDS-IPS)