Security system that monitors network traffic or system activity for malicious behaviour and policy violations.
An Intrusion Detection System (IDS) analyses network traffic or system logs to identify malicious activity, policy violations, or suspicious patterns. Network-based IDS (NIDS) monitors traffic flowing across network segments, while host-based IDS (HIDS) monitors activity on individual systems. IDS uses signature-based detection (matching known attack patterns) and anomaly-based detection (identifying deviations from normal behaviour). When suspicious activity is detected, IDS generates alerts for security teams to investigate. Unlike IPS, IDS monitors and alerts but doesn't automatically block threats.
Why It Matters
The DSC Perspective:
IDS provides visibility into what's happening on your network. While modern environments often use EDR and next-gen firewalls with built-in detection, understanding IDS helps you evaluate security tools and respond to compliance requirements asking about intrusion detection.
