home/glossary/intrusion detection and prevention mechanism

intrusion detection and prevention mechanism

nounverified·updated Sep 1, 2026

A control or capability — realized as software, hardware, or a combination — that monitors system or network activity to identify signs of unauthorized access or policy violation, and takes action to stop or limit detected threats. The phrase joins the well-established "intrusion detection" function (passive monitoring and alerting, as defined in NIST SP 800-94, which characterizes intrusion detection as monitoring events in a computer system or network and analyzing them for signs of possible incidents) with the prevention function (software that automates the monitoring of events in a computer system or network, analyzing them for signs of possible incidents, and attempting to stop detected possible incidents, per the NIST CSRC Glossary entry for IDPS). The phrase "intrusion detection and prevention mechanism" is compositional — it describes any implementation (tool, process, or control) that performs these two functions — whereas the established term of art in the field is "intrusion detection and prevention system (IDPS)," as codified by NIST SP 800-94, which covers IDPS technologies across four classes: network-based, wireless, network behavior analysis, and host-based.

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Control95%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
intrusion detection and prevention mechanisms
possessive
intrusion detection and prevention mechanism's
pluralpossessive
intrusion detection and prevention mechanisms'