intrusion detection and prevention mechanism
163591·updated Sep 1, 2026A control or capability — realized as software, hardware, or a combination — that monitors system or network activity to identify signs of unauthorized access or policy violation, and takes action to stop or limit detected threats. The phrase joins the well-established "intrusion detection" function (passive monitoring and alerting, as defined in NIST SP 800-94, which characterizes intrusion detection as monitoring events in a computer system or network and analyzing them for signs of possible incidents) with the prevention function (software that automates the monitoring of events in a computer system or network, analyzing them for signs of possible incidents, and attempting to stop detected possible incidents, per the NIST CSRC Glossary entry for IDPS). The phrase "intrusion detection and prevention mechanism" is compositional — it describes any implementation (tool, process, or control) that performs these two functions — whereas the established term of art in the field is "intrusion detection and prevention system (IDPS)," as codified by NIST SP 800-94, which covers IDPS technologies across four classes: network-based, wireless, network behavior analysis, and host-based.
Source
intrusion detectionthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
- Intrusion Detection and Prevention Systems | CSRC
- Intrusion detection and prevention system (IDPS) - Glossary | CSRC
- NIST Special Publication (SP) 800-94, Guide to Intrusion Detection and Prevention Systems (IDPS)
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
** This phrase is compositional rather than a term of art. The field standardizes on the established label *intrusion detection and prevention system (IDPS)* — software that automates the process of monitoring events in a computer system or network, analyzing them for signs of possible incidents, and attempting to stop detected possible incidents — while "mechanism" functions only as a generic structural substitute for "system," carrying no distinct meaning of its own. IDPS technologies are focused on identifying possible incidents, logging information about them, attempting to stop them, and reporting them to security administrators. Substituting "mechanism" for "system" in this phrase does not create a separate concept; it merely describes the same class of capability at a more abstract level. **VERDICT:** COMPOSITIONAL --- **Sources:** - NIST CSRC Glossary, *Intrusion Detection and Prevention System (IDPS)*: [csrc.nist.gov/glossary/term/intrusion_detection_and_prevention_system](https://csrc.nist.gov/glossary/term/intrusion_detection_and_prevention_system) — sourced from NIST SP 800-137. - NIST SP 800-94 Rev. 1 (Draft), *Guide to Intrusion Detection and Prevention Systems (ID
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- intrusion detection and prevention mechanisms
- possessive
- intrusion detection and prevention mechanism's
- pluralpossessive
- intrusion detection and prevention mechanisms'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A control or capability — realized as software, hardware, or a combination — that monitors system or network activity to identify signs of unauthorized access or policy violation, and takes action to stop or limit detected threats. The phrase joins the well-established "intrusion detection" function (passive monitoring and alerting, as defined in NIST SP 800-94, which characterizes intrusion detection as monitoring events in a computer system or network and analyzing them for signs of possible incidents) with the prevention function (software that automates the monitoring of events in a computer system or network, analyzing them for signs of possible incidents, and attempting to stop detected possible incidents, per the NIST CSRC Glossary entry for IDPS). The phrase "intrusion detection and prevention mechanism" is compositional — it describes any implementation (tool, process, or control) that performs these two functions — whereas the established term of art in the field is "intrusion detection and prevention system (IDPS)," as codified by NIST SP 800-94, which covers IDPS technologies across four classes: network-based, wireless, network behavior analysis, and host-based.DR-088 backfill from the noun definition column