We are independent & ad-supported. We may earn a commission for purchases made through our links.
Advertiser Disclosure
Our website is an independent, advertising-supported platform. We provide our content free of charge to our readers, and to keep it that way, we rely on revenue generated through advertisements and affiliate partnerships. This means that when you click on certain links on our site and make a purchase, we may earn a commission. Learn more.
How We Make Money
We sustain our operations through affiliate commissions and advertising. If you click on an affiliate link and make a purchase, we may receive a commission from the merchant at no additional cost to you. We also display advertisements on our website, which help generate revenue to support our work and keep our content free for readers. Our editorial team operates independently of our advertising and affiliate partnerships to ensure that our content remains unbiased and focused on providing you with the best information and recommendations based on thorough research and honest evaluations. To remain transparent, we’ve provided a list of our current affiliate partners here.
Technology

Our Promise to you

Founded in 2002, our company has been a trusted resource for readers seeking informative and engaging content. Our dedication to quality remains unwavering—and will never change. We follow a strict editorial policy, ensuring that our content is authored by highly qualified professionals and edited by subject matter experts. This guarantees that everything we publish is objective, accurate, and trustworthy.

Over the years, we've refined our approach to cover a wide range of topics, providing readers with reliable and practical advice to enhance their knowledge and skills. That's why millions of readers turn to us each year. Join us in celebrating the joy of learning, guided by standards you can trust.

What is an Intrusion Detection System?

By Sonal Panse
Updated: May 17, 2024
Views: 7,662
Share

Information networks can be highly susceptible to malicious attacks from worms, viruses and various other network threats, with regular new issues cropping up on these fronts. Such attacks can paralyze the networks, destroy important data and adversely affect productivity. To prevent this from happening, intrusion detection systems (IDS) are set up to protect information networks.

An intrusion detection system acts as a safeguard that detects attacks before or as they happen, alerts the system administration and then takes appropriate steps to disable the attacks, restoring the network to its normal working capacity. A certain degree of human supervision and investigation is usually required in intrusion detection systems, as the IDS is not completely foolproof. An intrusion detection system may, for instance, fail to identify some network threats or, in cases of busy networks, may not be able to check all the traffic that passes through the network.

In its day to day operation, the intrusion detection system monitors the user activity and traffic on the network, and keeps watch on the system configurations and the system files. If any abnormalities or attacks are detected, the intrusion detection system immediately sets up an alarm to bring the matter to the attention of the system administrator. The system may then proceed to deal with the network threats, or let the administrator decide on the best way to tackle the problem.

There are three main types of intrusion detection systems that together form an intrusion prevention system. The first is the network intrusion detection, which maintains a library of known network threats. The system checks around the Internet and constantly updates this library; this way the system is kept informed about the latest network threats and is able to better protect the network. The passing traffic is monitored and checked with the library, and if any known attack or any abnormal behavior matches with the ones in the library, the system gears up to block it.

The network node intrusion detection is the second part of the intrusion prevention system. It checks and analyzes the traffic that passes from the network to a specific host. The third part is the host intrusion detection system, which checks for any changes to the current system; if any files are modified or deleted, the host intrusion detection system sounds the alarm. It may either directly disable the attack or set up a new, improved security environment.

Share
WiseGeek is dedicated to providing accurate and trustworthy information. We carefully select reputable sources and employ a rigorous fact-checking process to maintain the highest standards. To learn more about our commitment to accuracy, read our editorial process.

Editors' Picks

Discussion Comments
Share
https://www.wisegeek.net/what-is-an-intrusion-detection-system.htm
Copy this link
WiseGeek, in your inbox

Our latest articles, guides, and more, delivered daily.

WiseGeek, in your inbox

Our latest articles, guides, and more, delivered daily.