Intrusion Detection System

Also known as:IDS

Intrusion DetectionDetectionThe capability to identify suspicious activity, attacks, or policy violations in time. System: Detects suspicious or anomalous activities on hosts or within networks. The control applies to network communicationNetwork CommunicationThe exchange of data between systems over network protocols and connections. or network accessNetwork AccessThe ability of a user, device, or workload to connect to and use network resources.. Effectiveness is achieved through restrictive rules, segmentation, continuous monitoringMonitoringThe continuous observation of systems, identities, networks, and controls for relevant changes., and coordinated response processesResponse ProcessA coordinated sequence of decisions and actions for handling security events and incidents..

How it works and where it fits

Intrusion Detection System connects data sources to detection or assessment logic. Raw records become security-relevant only when timing, identity, system context, and expected behavior are considered. Rules, correlations, statistical models, and analyst decisions may work together; no single method reliably covers every attack pattern.

Practical security relevance

Operational quality is reflected in coverage, data completeness, detection time, and false-alert workload. Data sources need owners, time synchronization, retention, and quality controls. Detections should be tested, versioned, and improved using real incidents. Every meaningful alert also requires triage guidance, escalation, and possible response actions.

  • Host-based Intrusion Detection SystemHost-based Intrusion Detection SystemMonitors events and changes directly on an endpoint or server.: Monitors events and changes directly on an endpoint or server.
  • Detection EngineeringDetection EngineeringSystematic development, testing, and maintenance of rules for attack detection.: Systematic development, testing, and maintenance of rules for attack detection.
  • Host Intrusion Prevention SystemHost Intrusion Prevention SystemEndpoint system for detecting and actively blocking suspicious activities.: Endpoint system for detecting and actively blocking suspicious activities.
  • Intrusion Prevention SystemIntrusion Prevention SystemAutomatically detects and blocks suspicious network traffic.: Automatically detects and blocks suspicious network traffic.