Security software on individual devices that detects and automatically blocks malicious activity.
A Host-based Intrusion Prevention System (HIPS) extends HIDS by automatically blocking detected threats on individual systems. HIPS can prevent unauthorised applications from running, block suspicious network connections, stop processes attempting malicious actions, and prevent changes to critical system files. This provides a last line of defence when network security and antivirus have failed. Modern endpoint protection platforms (EPP) and EDR solutions include HIPS capabilities alongside other protections.
Why It Matters
The DSC Perspective:
HIPS stops attacks that get past your other defences. It's particularly valuable for protecting servers running critical applications. Modern EDR includes HIPS functionality—ensure your endpoint protection can both detect and block threats.
