Home > Ask the Networking Experts > Network security with Puneet Mehta Questions & Answers > Intrusion detection vs. intrusion prevention
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Intrusion detection vs. intrusion prevention

Puneet Mehta EXPERT RESPONSE FROM: Puneet Mehta

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Network security news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 25 November 2006
What is the key difference between intrusion detection and intrusion prevention? If a firewall has intrusion prevention, is it assumed that intrusion detection is built in as well?

>
EXPERT RESPONSE

At a simple level, it's the difference between detection and prevention. IDS products are designed to inform you that something is trying to get into your system where IPS products actually attempt to prevent access.

Both IDS and IPS are designed for different purposes, but their technologies are similar. IDS is best used in situations where there is a need to explain what happened in an attack, whereas IPS stops attacks. An IDS system collects a lot of information that is not actionable from an IPS perspective, such as port scans and other reconnaissance.

An IDS analyzes traffic by comparing traffic to information in its database that contains patterns, called "signatures," found in known exploits. If certain traffic matches a pattern seen in an exploit, the IDS will send an alert to an administrator who can then take action to prevent the exploit or minimize the damage. IPS operates similar to IDS with one critical difference: IPS can block the attack itself; while an IDS sits outside the line of traffic and observes, an IPS sits directly in line of network traffic. Any traffic the IPS identifies as malicious is prevented from entering the network.

Check out TechTarget's IDS/IPS resources.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Network security with Puneet Mehta
Who is responsible for updating network firewalls?
How to locate the lost IP address of an Access Point (AP)
To simulate voice over IPSec VPNs which simulators work?
How to set passwords on folders in Windows 2003 servers
What commands allow network traffic to pass through PIX firewalls?
For an SMB firewall, what features should I look at?
Can users on my LAN view my computer from other machines?
Without an application-layer firewall, do I run network security risks?
Does a firewall need two static IPs for port forwarding?
What is layered defense approach to network security?

Network Security Best Practices
Securing the new network architecture
Why is LAN administration security important?
Securing the new network architecture: Security for distributed, dynamic networks
How to set passwords on folders in Windows 2003 servers
What are the best methods for handling rogue access points?
How to configure Windows Server 2008 advanced firewall MMC snap-in
Governance, compliance, security: How are these network problems?
Holidays are over; now beware the gadgets
Prevent unauthorized USB devices with software restriction policies, third-party apps
Introduction to firewalls: Types of firewall

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
anti-replay protocol  (SearchNetworking.com)
dynamic packet filter  (SearchNetworking.com)
HELLO packet  (SearchNetworking.com)
packet filtering  (SearchNetworking.com)
rule base  (SearchNetworking.com)
stateful inspection  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts