Intrusion Detection System

An intrusion detection system (IDS) is a device or software application that monitors a network or systems for malicious activity or policy violations. Any malicious activity or violation is typically reported either to an administrator or collected centrally using a security information and event management (SIEM) system.

Intrusion Detection System Methods

Signature-based detection

Signature-based IDS monitors packets in the Network and compares with pre-configured and pre-determined attack patterns known as signatures.

Statistical anomaly-based detection

An IDS which is anomaly-based will monitor network traffic and compare it against an
established baseline.

Stateful protocol analysis detection

This method identifies deviations of protocol states by comparing observed events with pre-determined profiles of generally accepted.

How Intrusion Detection Works