Intrusion detection systems analyze network traffic and system activity against known attack signatures and behavioral baselines. Intrusion prevention systems additionally block detected activity.
Effectiveness depends on tuning and on someone acting on alerts.
Alternative Names:
IDS, Intrusion Detection System
Why it Matters?
Detection capability is worthless without response capacity, and the recurring failure is alerts generated into a queue no one monitors. For firms without a security operations function, managed detection and response services provide the monitoring that makes the technology useful. The relevant question is who receives alerts and what happens outside business hours, since compromises are frequently timed for weekends and holidays.
Frequently Confused with
Related terms
Frequently asked questions
What makes intrusion detection effective?
What should be asked about coverage?





