intrusion detection and prevention mechanism
A control or capability — realized as software, hardware, or a combination — that monitors system or network activity to identify signs of unauthorized access or policy violation, and takes action to stop or limit detected threats. The phrase joins the well-established "intrusion detection" function (passive monitoring and alerting, as defined in NIST SP 800-94, which characterizes intrusion detection as monitoring events in a computer system or network and analyzing them for signs of possible incidents) with the prevention function (software that automates the monitoring of events in a computer system or network, analyzing them for signs of possible incidents, and attempting to stop detected possible incidents, per the NIST CSRC Glossary entry for IDPS). The phrase "intrusion detection and prevention mechanism" is compositional — it describes any implementation (tool, process, or control) that performs these two functions — whereas the established term of art in the field is "intrusion detection and prevention system (IDPS)," as codified by NIST SP 800-94, which covers IDPS technologies across four classes: network-based, wireless, network behavior analysis, and host-based.
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- intrusion detection and prevention mechanisms
- possessive
- intrusion detection and prevention mechanism's
- pluralpossessive
- intrusion detection and prevention mechanisms'