Host-Based vs. Network-Based
To protect specific servers or user devices the IDS/IPS is deployed at the host level.
Monitors traffic, processes, files’ access, devices’ access and data flows, memory allocations, and physical device characteristics (temperature, power consumption, movement, etc...).
To protect an organization (all devices and services) the IDS/IPS is deployed at the network level.
Monitors traffic at the packet and flow levels. May monitor the network at the physical level (radio, electric and optical signals).
Deployed at multiple network points:
Internet and WAN accesses;
Inter-zone communication links;
Wireless.
Last updated