Intrusion Detection System

Computer Network Security

Intrusion Detection System

Today , We will talk about another computer science subtopic , I thought since this topic is not present anywhere i should explain it.

Components of Intrusion Detection and Prevention Systems :

This is valid for all IDPS Products. IDPS solution in all products consist of some major components.

355.jpg

The typical Components in IDPS solutions are as follows :

  1. Agent or Sensors : agents and Sensors monitor and analyze activity. The term Sensors is used for those IDPS that monitor networks ,including network-based wireless and network behavior analysis technologies. The term Agents is used for host-based IDPS technologies.
  2. Management Server : A management server is a centralized device that receives information from the sensors or agents and manages them. Some management servers perform analysis on the event information that the sensors or agents provide and can identify events that the individual sensors or agents cannot. Matching event information from multiple sensors or agents, such as finding events triggered by the same IP address, is known as correlation. Management servers are available as both appliance and software-only products. Some small IDPS deployments do not use any management servers, but most IDPS deployments do. In larger IDPS deployments, there are often multiple management servers, and in some cases there are two tiers of management servers.
  3. Database Server : A database server is a repository for event information recorded by sensors, agents, and/or management servers. A lot of IDPSs give support for database servers.
  4. Console : Console is a program which provides interface for the IDPS’s users and administrators. Console software is typically installed onto standard desktop or laptop computers. Some consoles are used for IDPS administration only, such as configuring sensors or agents and applying software updates, while other consoles are used strictly for monitoring and analysis. Some IDPS consoles provide both administration and monitoring capabilities.

However, there can be other additional components too as we increase the complexity of our IDPS solution.

Thanks for reading till Now:) Hope it helps in preparation for college exams and interview.

Follow Up the Blog for more updates.