IDS vs. IPS: Definitions, Comparisons & Why You Need Both

IDS vs. IPS: Definitions, Comparisons & Why You Need Both

Thousands of businesses across the globe save time and money with Okta. Find out what the impact of identity could be for your organisation.

IDS vs. IPS: Definitions, Comparisons & Why You Need Both

Learn why Top Industry Analysts consistently name Okta and Auth0 as the Identity Leader

An intrusion detection system (IDS) monitors traffic on your network, analyses that traffic for signatures matching known attacks, and when something suspicious happens, you're alerted. In the meantime, the traffic keeps flowing. 

An intrusion prevention system (IPS) also monitors traffic. But when something unusual happens, the traffic stops altogether until you investigate and decide to open the floodgates again.

What will you vote for in the IDS vs. IPS debate? If you work in the IT space, you'll probably be asked this question at some point in your career. And if you're not sure how to answer right now, you're certainly not alone. 

Both systems have advantages and disadvantages. Because of that, some experts believe an IDS/IPS combination is the best way to protect a server.

 

IDS vs IPS

What Is an IDS? 

You want to protect the assets on your server. But you don't want to slow down the traffic, even if a problem occurs. An intrusion detection system (IDS) could be the solution you've been looking for. 

Five main types of IDS exist.

  1. Network: Choose a point on your network and examine all traffic on all devices from that point.
     
  2. Host: Examine traffic to and from independent devices within your network, and leave all other devices alone.
     
  3. Protocol-based: Place protection between a device and the server, and monitor all traffic that goes between them.
     
  4. Application protocol-based: Place protection within a group of servers and watch how they communicate with one another.
     
  5. Hybrid: Combine some of the approaches listed above into a system made just for you. 

No matter what type of IDS you choose, the