From the course: Cisco Network Security: Intrusion Detection and Prevention

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Host-based versus network IDS

Host-based versus network IDS - Cisco Routers Tutorial

From the course: Cisco Network Security: Intrusion Detection and Prevention

Start my 1-month free trial

Host-based versus network IDS

- [Instructor] Intrusion detection systems work to enforce the security policies on what traffic is allowed and what is denied. Intrusion detection can be host-based or network-based. Host-based monitors a single host. Network-based monitors the entire network. Host-based intrusion detection systems monitor a single host or endpoint that includes servers, workstations, and mobile devices. They can be fine-tuned to the specific application, workflow, or user role, host-based systems are operating system specific and work independently to monitor the events on a host for suspicious activity. Because the intrusion detection system is on the operating system, the encrypted traffic will be decrypted, and the intrusion detection system can examine the contents. Network-based intrusion detection systems monitor malicious and unauthorized activity on the network. Sensors are deployed at the network edge to monitor ingress and egress traffic and block network level attacks. Network intrusion…

Contents