
Imagine a security guard standing inside an office building watching people coming and going.
The guard has been trained to recognise suspicious behaviour.
They might notice someone:
- Trying several locked doors
- Carrying equipment they shouldn’t have
- Sneaking around restricted areas
- Repeatedly attempting to get past security
The guard can raise an alarm when something suspicious happens.
Now imagine a second guard who has the authority to physically stop the person from entering.
These two roles provide a useful analogy for Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS).
An IDS detects and alerts. An IPS detects and can actively block or prevent.
Both technologies are designed to identify potentially malicious network activity and are important detective and preventive security controls.
What Is an IDS?
IDS stands for Intrusion Detection System.
The important word here is detection. An IDS monitors activity and looks for signs that an attack or other suspicious behaviour may be taking place. When it identifies something suspicious, it generates an alert.
An IDS is similar to an intruder alarm.
Someone breaks a window, The alarm doesn’t necessarily stop the intruder itself – It tells people that there is a problem.
The point here is that an IDS generally observes rather than blocks the traffic.
What Is an IPS?
IPS stands for Intrusion Prevention System.
The important word here is prevention. An IPS performs a similar detection function to an IDS, but is positioned so that it can actively interfere with traffic to prevent any escalation of an attack.
An IPS is more like a security dog who can intervene when the window is broken
An IPS can potentially:
- Drop packets
- Block connections
- Reset sessions
- Block source addresses
- Quarantine traffic
depending on its configuration and capabilities.
This ability to actively interfere with malicious traffic is the key difference between detection and prevention.
The simplest distinction is:
| Technology | Main function |
|---|---|
| IDS | Detects suspicious activity and raises an alert |
| IPS | Detects suspicious activity and can automatically take action |
Where Are IDS and IPS Used?
IDS and IPS technologies can be deployed in several locations.
For example:
- Network perimeter
- Internal network
- Data centre
- Cloud environments
- Individual hosts
- Applications
A Network Intrusion Detection System (NIDS) monitors network traffic. It can be positioned to observe traffic travelling across important parts of the network. The NIDS analyses the traffic it can see and looks for suspicious patterns.
A Network Intrusion Prevention System (NIPS) is normally placed inline with the traffic.
Traffic has to pass through the IPS, which allows it to inspect the traffic and potentially block malicious packets.
Inline vs Passive
There is an important distinction between these two types
Passive monitoring is where The IDS receives a copy of network traffic. It isn’t directly in the traffic path.
Inline monitoring places the IPS directly in the traffic path. Traffic must pass through it which allows the system to block traffic if required.
Why Use a Passive IDS?
A passive IDS has an important advantage in that If it fails, it doesn’t necessarily interrupt network traffic.
The network can continue operating.
An IPS sitting inline has a different risk. Because traffic passes through an IPS, a failure could potentially affect connectivity.
This is why highly available deployments and appropriate failover mechanisms are important when considering network design.
Fail-Open vs Fail-Closed
Inline security devices can be configured with different failure behaviours.
- Fail-open preserves availability but may reduce security.
- Fail-closed preserves the security boundary but can affect availability.
Host-Based IDS
An IDS doesn’t have to monitor network traffic. A Host-Based Intrusion Detection System (HIDS) monitors activity on an individual computer or server.
It might monitor:
- File changes
- Processes
- System logs
- Configuration
- User activity
- System calls
Host-Based IPS
A Host-Based Intrusion Prevention System (HIPS) can go further and actively prevent suspicious activity on the host.
Modern endpoint security products (e.g. EDR) often combine many of these capabilities.
EDR vs HIDS/HIPS
This is where IDS/IPS terminology can become confusing.
Modern Endpoint Detection and Response (EDR) platforms provide much broader capabilities than traditional HIDS.
For example, EDR can monitor:
- Processes
- Files
- Network connections
- User activity
- Persistence
- Endpoint behaviour
and can often take response actions.
A useful way to think about it is:
HIDS/HIPS are focused on intrusion detection or prevention at the host level, while EDR provides broader endpoint visibility, detection, investigation and response.
Signature-Based Detection
One of the traditional ways IDS and IPS systems detect attacks is through signatures – known patterns associated with malicious activity.
If the traffic matches a known signature, the system can raise an alert or block it.
However, signature-based detection has an obvious weakness You can’t have a signature for an attack you don’t know about yet.
This is one reason modern IDS and IPS systems use additional detection techniques.
Anomaly-Based Detection
Anomaly detection looks for activity that differs significantly from what is considered normal.
This can potentially identify previously unknown attacks.
Behaviour-Based Detection
Modern security systems can also look for suspicious behaviour.
Rather than looking for one specific attack signature, the system considers what the traffic is actually doing.
Reputation-Based Detection
Some systems can also use threat intelligence and reputation information.
This allows security systems to benefit from information about known malicious infrastructure.
Deep Packet Inspection
Some IDS/IPS technologies can perform deep packet inspection.
Rather than looking only at basic network information such as the data in an IP header:
Source IP
Destination IP
Port
Protocol
they may inspect the actual contents of the traffic.
This can provide much greater visibility.
The Encryption Challenge
Encrypted traffic creates an important problem for network-based IDS and IPS.
If the security device cannot see inside the encrypted connection, it may not be able to inspect the application payload.
This is one reason organisations may use techniques such as TLS inspection where appropriate.
TLS Inspection
A security device can sometimes decrypt and inspect encrypted traffic before re-encrypting it.
This provides greater visibility but introduces:
- Privacy considerations
- Performance overhead
- Certificate-management requirements
- Additional complexity
It also means the security device becomes part of the trust model for the encrypted connection.
False Positives & False Negatives
IDS and IPS systems can make mistakes.
A false positive occurs when legitimate activity is incorrectly identified as malicious. Too many false positives can overwhelm security teams.
A false negative occurs when malicious activity isn’t detected. This is potentially much more serious because the security team may not know an attack is happening.
IDS/IPS Rules
Administrators can configure rules to determine what the system should detect or block.
Rules can be specific or highly sophisticated.
IDS and IPS rule need regular tuning.
Security teams may need to:
- Enable useful rules
- Disable irrelevant rules
- Adjust thresholds
- Reduce false positives
- Update signatures
- Investigate unexpected detections
Signature Updates
Attack techniques evolve constantly and the mechanisms to detect the changes must change accordingly. IDS and IPS systems therefore need updated detection signatures.
An IDS/IPS that hasn’t been updated may have significantly reduced effectiveness.
IDS/IPS and Zero-Day Attacks
A zero-day attack is particularly challenging because there may not yet be a known signature.
However, modern detection systems may still identify suspicious behaviour through:
- Anomaly detection
- Behaviour analysis
- Protocol analysis
- Exploit detection
- Threat intelligence
This isn’t guaranteed, but it can provide another layer of protection.
IDS/IPS and Port Scanning
One common activity that IDS/IPS systems can detect is port scanning.
An attacker may send connections to many ports, and the security system may recognise this pattern as reconnaissance.
An IDS might alert that a port scan has been detected, whereas the IPS could potentially block or rate-limit the source.
IDS/IPS and Malware
IDS/IPS can also detect network behaviour associated with malware.
This can be useful even if the malware itself wasn’t detected on the endpoint.
IDS/IPS and Data Exfiltration
Attackers will often attempt to move stolen information out of an organisation.
IDS/IPS may contribute to detecting unusual outbound traffic.
However, data-loss prevention and other controls may be more appropriate for identifying the actual sensitive content.
IDS/IPS vs Firewalls
IDS/IPS and firewalls are complementary technologies, but they perform different jobs.
A firewall primarily makes decisions based on things such as:
- Source
- Destination
- Port
- Protocol
- Application
- Identity
An IDS/IPS looks more deeply for suspicious or malicious activity.
A firewall might allow some HTTPS traffic to pass through, but the traffic travelling over HTTPS could contain a malicious request.
An IDS/IPS may be able to recognise the attack.
This demonstrates Defence in Depth.
IDS/IPS and Network Segmentation
IDS/IPS can be particularly useful around important network segments.
For example between a DMZ and the internal network, or between the normal network, and the segment that contains the sensitive data servers.
Monitoring traffic between security zones can help identify attempts at lateral movement.
This can help detect an attacker who has already bypassed the perimeter defences.
IDS/IPS and SIEM
IDS and IPS systems generate valuable security events which can be sent to a SIEM.
The SIEM can then combine the IDS/IPS alert with information from:
- EDR
- Firewalls
- Authentication systems
- DNS
- VPN
- Cloud platforms
IDS/IPS + EDR + SIEM
This creates a powerful combination.
- The IDS sees the network behaviour.
- EDR sees what’s happening on the endpoint.
- The SIEM brings the information together.
IDS/IPS + SOAR
A SOAR platform can automate responses to IDS/IPS alerts.
A response might include:
- Blocking an IP
- Isolating a host
- Disabling an account
- Creating an incident ticket
- Alerting an analyst
IDS/IPS Limitations
IDS and IPS are powerful technologies, but they aren’t magic.
They can struggle with:
- Encrypted traffic
- Unknown attacks
- False positives
- False negatives
- High traffic volumes
- Evasion techniques
- Poorly configured rules
- Blind spots in the network
They should therefore be considered one layer of Defence in Depth.
In Summary
An Intrusion Detection System (IDS) monitors activity and alerts when it identifies potentially malicious behaviour.
An Intrusion Prevention System (IPS) performs similar detection but can actively block or interfere with malicious traffic.
IDS
- Primarily detective
- Usually passive
- Generates alerts
- Doesn’t normally interfere with traffic
IPS
- Detective and preventive
- Usually inline
- Can block malicious traffic
- Can reset or terminate connections
- Requires careful configuration
They can operate at different levels:
- Network IDS/IPS
- Host-based IDS/IPS
- Application-aware detection
- Cloud-based monitoring
They can use:
- Signatures
- Anomaly detection
- Behaviour analysis
- Protocol analysis
- Threat intelligence
- Deep packet inspection
And they work particularly well with:
- Firewalls
- Network Segmentation
- EDR
- SIEM
- SOAR
- Logging and Auditing
- Threat Intelligence
- Incident Response
Neither technology can guarantee that every attack will be detected. Attackers can use encryption, evasion techniques, previously unknown attacks and other methods to avoid detection.
That’s why IDS and IPS should not be viewed as a replacement for other security controls.
Instead, they form another layer in Defence in Depth.
The goal isn’t simply to stop every attack at the perimeter. It’s to detect suspicious activity wherever possible and prevent it from causing harm.
IDS sees the attack. IPS can stop the attack. Together, they provide another layer of defence.