Detect & Prevent Intrusions
IDS detects suspicious activity, while IPS actively blocks malicious traffic.
IDS → Monitor + Alert IPS → Monitor + Block
NIDS → Network-based HIDS → Host-based
Traffic → Analyze → Detect → Alert/Block
Signature-based → Known attacks Anomaly-based → Unusual behavior
Snort → IDS/IPS Suricata → Advanced detection OSSEC → Host-based IDS