Intrusion Prevention System

Ranked #6,225 in Computers & Electronics, #129,665 overall

Introduction: What is an Intrusion Prevention System?

An intrusion prevention system a/k/a IPS system is an appliance used in a network security strategy, and is an extension of the intrusion detection system. The appliance monitors networks or systems for threats. Once identified a threat is assessed and either drops the packets blocks the activity or sends an alert to the appropriate person for review.

There are two types of, network-based or host-based intrusion prevention systems. The network-based system monitors all network traffic, while the host-based is specific to either an IP address or computer.

This lens focuses on strengths, weaknesses and the future of network intrusion preventions systems.

I am by no means an expert, and would love any feedback or opinions that can enhance the information on this page!

Finshake

A Blog by Joel Esler

Loading Fetching RSS feed... please stand by

Intrusion Prevention System: Strengths

Intrusion prevention systems were a leap forward from their predecessors, intrusion detection systems. At first, these new systems were spotty, and network security professionals were wary of using them. They were slow and drained valuable bandwidth, and often times blocked the wrong traffic.

Now, 10 years later, the intrusion prevention industry has matured and the top competitors have been able to lower or eliminate the bandwidth utilized and ensure customized settings for blocking threats while still letting in the 'good guys.'

Major strengths of intrusion prevention systems are:

  • Automatically Identifies and Blocks Threats

  • Reduces Time Spent Reviewing Log Files to Identify Threats

  • Reduces Need for Manpower to Monitor Threats

  • Enhances Network Security Architecture

Intrusion Prevention System: Litmus Test

What do you think the strength/weaknesses of IPS are?

Loading Fetching blurbs now... please stand by

Daniel L. Messana says:

strength: protecting potentially bad/harmfull traffic

weakness: blocking false-positives (good traffic that is seen as bad)

 

Intrusion Prevention System: Weaknesses

While intrusion prevention systems provide a baseline for network security, it is no longer enough. While improved, these systems were created for the static networks of yesteryear. Wireless devices, virtualization, cloud environments, and pda devices have all made today's networks more dynamic. The threats to these networks have adapted to take advantage of these changes, but the majority of intrusion prevention systems have not.

Weaknesses of many current intrusion prevention systems are:

  • Lack of Network Visibility

  • Lack of User Visibility

  • Inability to Adapt to Network Changes in Real-Time

Poll: IDS or IPS?

Loading poll. Please Wait...

Intrusion Prevention System: Books

Loading

Reader Feedback

submit
  • Reply
    Dec 2, 2009 @ 3:18 am | delete
    Great lens! 5*****
  • Reply
    Margaret_Schaut May 20, 2009 @ 11:38 pm | delete
    Unfortunately this is becoming all too important to know about and understand. Love the graphics, which really clarify things. I'd like to see you Squidooing more- I get the idea that you're pretty talented. Blessed and the works!
  • Reply
    lokipro Mar 20, 2009 @ 11:13 am | in reply to cannedguds | delete
    Thanks for stopping by and for the ego boost ;)... I gave your short stories some * love too. :) I'm hoping to get some more info on the page about creating a home IPS too... or could be a new lens!
  • Reply
    cannedguds Mar 20, 2009 @ 11:08 am | delete
    this is the 1st time i've read something about IPS but I'm interested to know more and your lens is the first best lens for anyone to go through to learn about Intrusion Prevention System! Thanks for sharing this and thanks for visiting my lens. I'm very grateful you like the short "story" about the mother-in-law....5 *s for your lens!
  • Reply
    Susan52 Mar 13, 2009 @ 11:38 am | delete
    I don't know much about the subject (just what I read on this page) but I do know that I like your lens. Well done!
  • Load More

Resources for Intrusion Prevention Systems

Gartner Magic Quadrant for Intrusion Prevention System Appliances, 1H08
Gartner is a company that provides neutral analysis of a wide range of industries. This links leads to a PDF of their review of the Intrusion Prevention System Industry. This report was last updated in 2008.
Breaking Point Testing Methodologies
BreakingPoint tests various networking devices, including intrusion prevention systems.
IPS System by Sourcefire
Sourcefire, creators of Snort, offers a rules-based intrusion prevention system (IPS) based on a powerful combination of vulnerability- and anomaly-based inspection methods.
Intrusion Prevention System - Enterprise Threat Management
In addition to their standard intrusion prevention system, Sourcefire offers a suite of tools that provides one with complete network visibility. Their tools allow network professionals to see what is on their network, in real-time.

Cisco Intrusion Prevention System Module Video Data Sheet

powered by Youtube

Wordle

This image was created at Wordle

Sourcefire VRT Blog

Loading Fetching RSS feed... please stand by

by

lokipro

Just a curious squid, having fun with Squidoo!

Feeling creative? Create a Lens!