Intrusion Detection System / Prevention Flashcards
IDS/IPS
HIDS ( Host- based Intrusion detection system)
Software installed on a system such as a workstation or server.
NIDS ( Network-based intrusion detection )
A sensors placed on a router and firewall that monitors and reports network traffic not able to detect anomalies on individual systems or workstations
Signature based
A database of known vulnerabilities or known attack patterns
HIPS ( host based Intrusion Prevention system )
Stops attacks in progress by detecting and blocking attacks on workstations and servers
Behavior based
Anomaly based is also called
IPS ( intrusion Prevention system)
Stops Serious attacks in progress by detecting and blocking attacks on systems and networks
Anomaly Based
Can detect unknown anomalies. They start with a performance baseline of normal behavior and then compare network traffic against this baseline. When traffic differs significantly from the baseline the IDS sends an alert.
Heuristic
Examine activity and make decisions that are outside the scope of a signature or definition database. This can be effective at discovering zero-day exploits.
NIPS network Intrusion protection system
Protects the internal network by detecting malicious traffic and preventing attacks from reaching the internal network.
Intrusion detection system IDS
Detected attacks on systems and networks and alerts administrator