Intrusion Detection

Intrusion Detection

Intrusion Detection

Intrusion detection systems analyze network traffic and system activity against known attack signatures and behavioral baselines. Intrusion prevention systems additionally block detected activity.

Effectiveness depends on tuning and on someone acting on alerts.

Alternative Names:

IDS, Intrusion Detection System

Why it Matters?

Detection capability is worthless without response capacity, and the recurring failure is alerts generated into a queue no one monitors. For firms without a security operations function, managed detection and response services provide the monitoring that makes the technology useful. The relevant question is who receives alerts and what happens outside business hours, since compromises are frequently timed for weekends and holidays.

Frequently Confused with

Related terms

Frequently asked questions

What makes intrusion detection effective?

What makes intrusion detection effective?

Response capacity. Alerts generated into an unmonitored queue provide no protection, which is why managed detection services exist.

What should be asked about coverage?

What should be asked about coverage?

Who receives alerts and what happens outside business hours, since intrusions are frequently timed for weekends and holidays.