IPSs - A REVIEW cont... (The IPS Mechanism)

  Graphical View | Text Only View | Mobile/PDA View | Print View
community pagestech resource links




 Main Pages   Core Services   Core Products   Other   Info Pages 
-Home- -Open Source- -eCommerce- -Free Articles & Links- -Web Accessibility-
-Contact us- -Software Training- -Bespoke Software- -Technical Support- -Find your IP-
-Networking- -Web Design & SEO- -Prince Projects-

 

-- PAGE 3 --

<< previous page next page >>



Intrusion Prevention Systems – A Review cont...

The IPS Mechanism

When discussing Intrusion Prevention Systems, there is a formula that is commonly used:

IPS = IDS + Firewall

While this formula provides a useful means of conceptualizing the basic make-up of an Intrusion Prevention System, it is also a simplistic model, concentrating upon form over substance, and more explanation is needed.

A firewall is a system which applies an access control policy. It checks data traffic passing through, and blocks data packets which do not match its security policies. An Intrusion Detection System (IDS) monitors network or system performance, looks for behavior contrary to its security policies and recognizable attack signatures, and it triggers alarms accordingly. So, a firewall rejects obvious attacks, while suspicious traffic will pass through. In turn, the IDS monitors all the data within the network, notifying the network administrator of attacks at a point where the attack is actually live and inside the network. In other words, neither the IDS nor the firewall is capable of blocking attacks themselves at the point at which an intrusion is identified.

The IPS then, is something more than an IDS plus a firewall. The IPS is designed as an embedded system which creates plenty of filters to prevent different kinds of attacks, such as those from hackers, worms, viruses, DoS and other malicious traffic, in advance so that enterprise networks do not suffer any loss even if the latest security patch has not yet been applied. The deployment of an IPS is based upon an “in-line” module: data passes through the IPS device from one end of a single data channel, only the data that is checked and validated by IPS engine, is allowed to pass through to the other end of the data channel. In this scenario, packets containing attack signatures along with their source packets are cleaned out of the network.


Figure 2



-- PAGE 3 --

<< previous page next page >>


Page 1 | Page 2 | Page 3 | Page 4 | Page 5 | Page 6 | Page 7 | Page 8 | Page 9 | Page 10 | Page 11 | Page 12 | Glossary | References




Xuhua Ji, September 2007

(You are free to reproduce any of the information in this article or part thereof, so long as the byline remains intact and a link is provided back to this page)






Delicious bookmark    add to del.icio.us

Comment on this article >>




speak to a consultant   0870 393 0044

   free articles

  1. Internet marketing tips - onsite SEO (pdf opens in a new window) read more >>

  2. Email messaging services and protocols (pdf opens in a new window) read more >>

  3. Search engine optimisation: an integrated approach (opens in a new window) read more >>

  4. How to find a good web designer or eCommerce provider - read more >>

  5. How to keep old computers out of landfill - read more >>

  6. How enterprises can save money on software licenses - read more > >

  7. More green computing tips for businesses - read more > >

  8. How to find a domain name - read more > >

  9. how to find a web hosting package - read more > >

  10. IPSs- an intro read more > >

   free links

  1. free technical resource links read more > >

  2. list of free business directories read more > >





We cover Leeds, Bradford, Halifax, Huddersfield, Harrogate, Castleford, Wakefield and York, Kirklees, Calderdale, Humberside, and the surrounding West Yorkshire and North Yorkshire areas. Web services and software development are available to companies throughout the UK and worldwide.

     HOME | OPEN SOURCE | eCOMMERCE | ACCESSIBILITY | CONTACT | IT TRAINING | SOFTWARE | WEB DESIGN | SEO | NETWORKS | PROJECTS | ARTICLES


Valid XHTML 1.0 Transitional    Designed using W3C compliant XHTML and CSS   -Green Company-   -Site Map-   -Contact-   -© FSI 2008-