Files
notes/projects/OPNsense/Initial-Notes/OPNsense_IDS-and-IPS.md
2025-02-08 21:56:24 +01:00

4 lines
452 B
Markdown

## Introduction
An _Intrusion Detection System_ (IDS) watches network traffic for suspicious patterns and can alert operators when a pattern matches a database of known behaviors.
An _Intrusion Prevention System_ (IPS) goes a step further by inspecting each packet as it traverses a network interface to determine if the packet is suspicious in some way. If it matches a known pattern the system can drop the packet in an attempt to mitigate a threat.