Intrusion detection and prevention systems (IDPS) are used to inform IT administrators and security staff of anomalies and attacks on IT infrastructure and applications. These tools detect malware, socially engineered attacks, and other web-based threats. IDPS also provide preemptive intrusion prevention capabilities for internal threats and potentially compromised systems.
Intrusion detection and prevention systems monitor systems for abnormal behavior and potential vulnerabilities that can leave a business susceptible to cyberattacks. Companies choose to adopt these to protect their sensitive business information and ensure their computing infrastructure performs as needed.
Some next-generation firewall software offer intrusion detection and prevention capabilities. But the main functionality of firewall tools will be controlling network access, rather than monitoring network behavior.
To qualify for inclusion in the Intrusion Detection and Prevention Systems (IDPS) category, a product must:
Monitor IT systems for abnormal behavior and misuse
Inform administrators of abnormal protocol activity
Monitor the performance of IT hardware and security components
Provide blocking mechanisms for web-based threats