Sec 130 Coreen L. Petrella
Intrusion Detection System (IDS) Late 1990’s Works like a Burglar Alarm It detects a violation and activates an alarm Audible and/or visual (noise and lights) Silent ( ) System administrators can choose the configurations
Intrusion Prevention System (IPS) Extension of IDS technology Can detect an intrusion and also prevent it from successfully attacking the organization by means of an active response
Intrusion Detection and Prevention System (IDPS) IDS and IPS coexist Current anti-intrusion technologies IDPS is the combined term
Reasons to acquire and use an IDPS Prevent problem behaviors by increasing the perceived risk of discovery and punishment for those who would attack or abuse the system Detect attacks and other security violations that are not prevented by other security measures Detect and deal with the preamble to attacks
Reasons continued … Document the existing threat to an organization Act as quality control for security design and administration Provide useful information about intrusions that do take place, allowing improved diagnosis, recovery, and correction of causative factors