Optiv Cybersecurity Dictionary

What are Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)?

The key difference between IDS and IPS lies in “detection” vs. “prevention.” Intrusion Detection Systems (IDS) monitor and scrutinize network traffic for known cyberattack signatures. Intrusion Prevention Systems (IPS), which reside between the internal network and external networks (like the internet), reject incoming traffic when it indicates a recognized security threat profile.


Threat profiles take into account many factors, including security policy violations, malware and port scanners.


