~/ learn/ comp-400/ cards/ Deciding instead of reporting
1 of 7

What distinguishes an intrusion prevention system from an intrusion detection system?

What distinguishes an intrusion prevention system from an intrusion detection system?

Answer

It can block or modify the activity it detects, rather than only reporting it

Options - A. It can block or modify the activity it detects, rather than only reporting it - B. It uses anomaly detection, whereas an IDS uses signatures - C. It is always host-based, whereas an IDS is always network-based - D. It can inspect encrypted traffic that an IDS cannot Why - A. Correct — an IPS is an IDS with the authority to act: blocking or modifying packets at a perimeter or into a host, or blocking or modifying system calls on a host. - B. Both use either approach. Detection technique is an independent axis from whether the system may act. - C. Both come in host-based, network-based and distributed forms. Placement is another independent axis. - D. Encryption blinds an inline inspector exactly as it blinds a passive one. Neither can read what it cannot decrypt. Keep the axes separate: WHAT it detects with, WHERE it sits, and WHETHER it may act. Only the last one separates IDS from IPS.

Stallings & Brown, Computer Security 5e, ch9 sections 9.6-9.8

space flip · ← → navigate · esc to exit
NORMAL ~/memra/library/5d3c9f53-5ba1-46d4-b44b-32f076377327/flashcard utf-8 LF