Investigating IPS/IDS alerts
The Intrusion Prevention System (IPS) is a security appliance that is deployed inline in a network to constantly watch the network traffic, preventing threats and any malicious attempts to exploit a known vulnerability (see Figure 13.1):
Figure 13.1 – An IPS layout
As you see in the preceding figure, the IPS is implemented inline for data communication, which allows it to monitor the network traffic between networks to prevent cyber threats.
The Intrusion Detection System (IDS) is a security appliance that is deployed out of band from data communication by using port mirroring, a SPAN port, or a network tap to capture network traffic, detecting threats, anomalies, and any malicious attempts to exploit a known vulnerability (see Figure 13.2):
Figure 13.2 – An IDS layout
As you can see in the preceding figure, the IDS is implemented out of band from data communication by using a...