Dictionary · NIST SP 800-36
L2 — definitions grouped by regulatory framework.
Nouns
3 senses- Host=based Intrusion Detection Systems
IDSs which operate on information collected from within an individual computer system. This vantage point allows host-based IDSs to determine exactly which processes and user accounts are involved in a particular attack on the Operating System. Furthermore, unlike network-based IDSs, host-based IDSs can more readily “see” the intended outcome of an attempted attack, because they can directly access and monitor the data files and system processes usually targeted by attacks.
- Intrusion prevention system
System(s) which can detect an intrusive activity and can also attempt to stop the activity, ideally before it reaches its targets.
- Network-Based Intrusion Detection Systems
IDSs which detect attacks by capturing and analyzing network packets. Listening on a network segment or switch, one network-based IDS can monitor the network traffic affecting multiple hosts that are connected to the network segment.