Security system that detects and automatically blocks malicious network traffic or activity.
An Intrusion Prevention System (IPS) extends IDS by automatically taking action to block detected threats. When malicious traffic is identified, IPS can drop packets, block connections, or quarantine affected systems without waiting for human intervention. IPS sits inline with network traffic (rather than just monitoring a copy), enabling real-time blocking. This active protection comes with risk—false positives can block legitimate traffic. Careful tuning is essential to balance security with business continuity. Modern next-generation firewalls typically include IPS functionality.
Why It Matters
The DSC Perspective:
IPS provides automatic protection against known attacks. It's particularly valuable for blocking automated attacks and exploit attempts. Your next-generation firewall likely includes IPS—ensure it's enabled and properly tuned.
