IDS & IPS Flashcards
What does an IDS do?
Intrusion Detection System
Logs and alerts
Only detects
What does an IPS do?
Intrusion Prevention System
Logs, alerts, takes action
Detects and reacts
What is a NIDS?
Network Intrusion Detection System
responsible for detecting unauthorized network access or attacks
Monitors the traffic coming in and out of a network
What is a HIDS?
Host-Based IDS
configured to look at suspicious network traffic going to or from a single server or endpoint,
What is a WIDS?
Wireless IDS
focused on detecting attempts to cause a denial of service on the wireless network
What are Signature-Based IDS?
analyze traffic based on defined signatures, and they can only recognize attacks based on the previously identified attacks that exist inside of its database.
What are the two types Signature-Based IDS are broken up into?
- Pattern matching: focus on a specific pattern of steps that are being recognized during an attack
- Stateful-Matching: focus on a known baseline of a system and reporting any changes to that state
What is Pattern Matching more common in?
NIDS & WIDS
What is Stateful Matching more commonly used with?
HIDS
What are Anomaly-Based IDS?
analyze traffic and compare it to a normal baseline of traffic to determine whether there is a threat that’s occurring.
aka Behavioral-Based IDS
What are IPS?
Intrusion Prevention System
Scan traffic for malicious activity and take action to stop it