Intrusion Detection System (IDS)
Definition
A network or host-based monitoring system that analyses traffic or system behaviour against a rule set (signature-based) or a statistical baseline (anomaly-based) and generates alerts on matches. A network IDS (NIDS) such as Snort or Suricata sits on a span or tap port; a host IDS (HIDS) runs on individual endpoints.
- Detection types
- Signature-based and anomaly-based
- NIDS examples
- Snort, Suricata
- NIDS placement
- Span or tap port
- HIDS placement
- Runs on individual endpoints
Common questions
What forensic value does IDS output have?+
Alert logs and captured packet payloads timestamp and characterise attack traffic, often giving investigators the earliest record to correlate against later host-level compromise indicators.
What limitation must examiners account for?+
Signature-based IDS only flags known attack patterns, so an absence of alerts does not prove an absence of intrusion, particularly for novel or encrypted attack traffic.
Related terms
- DHCP Lease Log
- A record maintained by a Dynamic Host Configuration Protocol server that maps each IP address assignment to the requesting device's MAC address,...
- NetFlow
- A network protocol (originally Cisco, now standardised as IPFIX under RFC 7011) that records metadata about IP traffic flows: source and destination...
- PCAP (Packet Capture)
- A file format (and the process of creating it) that records every byte of every network packet passing a capture point, including...
- RADIUS Log
- An authentication, authorisation, and accounting record produced by a Remote Authentication Dial-In User Service server. Each entry records the username, authenticating device...
- Syslog
- A standardised protocol (RFC 5424) for transmitting log messages from network devices to a centralised log server. Routers, switches, firewalls, and servers...