We are independent & ad-supported. We may earn a commission for purchases made through our links.

Advertiser Disclosure

Our website is an independent, advertising-supported platform. We provide our content free of charge to our readers, and to keep it that way, we rely on revenue generated through advertisements and affiliate partnerships. This means that when you click on certain links on our site and make a purchase, we may earn a commission. Learn more.

How We Make Money

We sustain our operations through affiliate commissions and advertising. If you click on an affiliate link and make a purchase, we may receive a commission from the merchant at no additional cost to you. We also display advertisements on our website, which help generate revenue to support our work and keep our content free for readers. Our editorial team operates independently from our advertising and affiliate partnerships to ensure that our content remains unbiased and focused on providing you with the best information and recommendations based on thorough research and honest evaluations. To remain transparent, we’ve provided a list of our current affiliate partners here.

What is an Intrusion Detection System?

By Sonal Panse
Updated May 17, 2024
Our promise to you
WiseGEEK is dedicated to creating trustworthy, high-quality content that always prioritizes transparency, integrity, and inclusivity above all else. Our ensure that our content creation and review process includes rigorous fact-checking, evidence-based, and continual updates to ensure accuracy and reliability.

Our Promise to you

Founded in 2002, our company has been a trusted resource for readers seeking informative and engaging content. Our dedication to quality remains unwavering—and will never change. We follow a strict editorial policy, ensuring that our content is authored by highly qualified professionals and edited by subject matter experts. This guarantees that everything we publish is objective, accurate, and trustworthy.

Over the years, we've refined our approach to cover a wide range of topics, providing readers with reliable and practical advice to enhance their knowledge and skills. That's why millions of readers turn to us each year. Join us in celebrating the joy of learning, guided by standards you can trust.

Editorial Standards

At WiseGEEK, we are committed to creating content that you can trust. Our editorial process is designed to ensure that every piece of content we publish is accurate, reliable, and informative.

Our team of experienced writers and editors follows a strict set of guidelines to ensure the highest quality content. We conduct thorough research, fact-check all information, and rely on credible sources to back up our claims. Our content is reviewed by subject matter experts to ensure accuracy and clarity.

We believe in transparency and maintain editorial independence from our advertisers. Our team does not receive direct compensation from advertisers, allowing us to create unbiased content that prioritizes your interests.

Information networks can be highly susceptible to malicious attacks from worms, viruses and various other network threats, with regular new issues cropping up on these fronts. Such attacks can paralyze the networks, destroy important data and adversely affect productivity. To prevent this from happening, intrusion detection systems (IDS) are set up to protect information networks.

An intrusion detection system acts as a safeguard that detects attacks before or as they happen, alerts the system administration and then takes appropriate steps to disable the attacks, restoring the network to its normal working capacity. A certain degree of human supervision and investigation is usually required in intrusion detection systems, as the IDS is not completely foolproof. An intrusion detection system may, for instance, fail to identify some network threats or, in cases of busy networks, may not be able to check all the traffic that passes through the network.

In its day to day operation, the intrusion detection system monitors the user activity and traffic on the network, and keeps watch on the system configurations and the system files. If any abnormalities or attacks are detected, the intrusion detection system immediately sets up an alarm to bring the matter to the attention of the system administrator. The system may then proceed to deal with the network threats, or let the administrator decide on the best way to tackle the problem.

There are three main types of intrusion detection systems that together form an intrusion prevention system. The first is the network intrusion detection, which maintains a library of known network threats. The system checks around the Internet and constantly updates this library; this way the system is kept informed about the latest network threats and is able to better protect the network. The passing traffic is monitored and checked with the library, and if any known attack or any abnormal behavior matches with the ones in the library, the system gears up to block it.

The network node intrusion detection is the second part of the intrusion prevention system. It checks and analyzes the traffic that passes from the network to a specific host. The third part is the host intrusion detection system, which checks for any changes to the current system; if any files are modified or deleted, the host intrusion detection system sounds the alarm. It may either directly disable the attack or set up a new, improved security environment.

WiseGEEK is dedicated to providing accurate and trustworthy information. We carefully select reputable sources and employ a rigorous fact-checking process to maintain the highest standards. To learn more about our commitment to accuracy, read our editorial process.

Discussion Comments

WiseGEEK, in your inbox

Our latest articles, guides, and more, delivered daily.

WiseGEEK, in your inbox

Our latest articles, guides, and more, delivered daily.