home/glossary/Intrusion detection

Intrusion detection

nounid 3017·updated May 9, 2026
verified

Techniques that attempt to detect unauthorized entry or access into a computer or network by observation of actions, security logs, or audit data; detection of break-ins or attempts, either manually or via software expert systems that operate on logs or other information available on the network.

MWE

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems4 citations · 4 machine-matched · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.05.d ¶ 103.01.07.b ¶ 103.04.06.d ¶ 203.14.06.c ¶ 2

Classifications

Entity Type

Capability92%llm-generatedllm:claude-haiku-4-5

Sensitivity

unclassified

Information Class

unclassified

Variants

plural
Intrusion detections
possessive
Intrusion detection's
pluralpossessive
Intrusion detections'

Framework definitions

SANS Glossary of Security Terms1 senseview framework →
§1
A security management system for computers and networks. An IDS gathers and analyzes information from various areas within a computer or a network to identify possible security breaches, which include both intrusions (attacks from outside the organization) and misuse (attacks from within the organization).
National Initiative for Cybersecurity Careers and Studies (NICCS) Cybersecurity Lexicon1 senseview framework →
§1
The process and methods for analyzing information from networks and information systems to determine if a security breach or security violation has occurred.
ISACA Cybersecurity Glossary1 senseview framework →
§1
The process of monitoring the events occurring in a computer system or network to detect signs of unauthorized access or attack
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
Techniques that attempt to detect unauthorized entry or access into a computer or network by observation of actions, security logs, or audit data; detection of break-ins or attempts, either manually or via software expert systems that operate on logs or other information available on the network.
NIST SP 800-171r31 senseview framework →
§1 · attested_usage_pack_match
No definition is given in NIST SP 800-171r3. The term is attested in use at 4 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
Techniques that attempt to detect unauthorized entry or access into a computer or network by observation of actions, security logs, or audit data; detection of break-ins or attempts, either manually or via software expert systems that operate on logs or other information available on the network.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.