What is the Difference Between Host & Network Intrusion Detection Sensors?

What is the Difference Between Host & Network Intrusion Detection Sensors? thumbnail
Computer and network attacks can be detected with intrusion detection sensors.

A network intrusion occurs when data in the form of e-mail, an audio or video program, or data file enters a private network. The private network can be a home or business network. A public network would be on the Internet.

  1. Network-Based Intrusion Detection

    • Network-based intrusion detection places sensors inside a private network, between routers or a switch. This breaks up a network into multiple smaller networks.The sensors test programs at the network level, and the sensors recognize the activity of the program as normal or abnormal, based on existing comparison parameters. The sensor determines if the program is from outside the network, and how to treat it if it is.

    Host-Based Intrusion Detection

    • The host-based system of intrusion detection means that the PC is the source of the detection. For example, e-mail might be circulating around the network, but when it reaches the PC, the host engages the software to detect the status of the email. The software analyzes data through application and operating system event logs and file attributes.

    Example

    • Network intrusion occurs when ordinary programs perform in unexpected ways. For example, an email might suddenly start to copy itself repeatedly, or it might force your network or PC to forward emails to everyone in your address book. To prevent this, place a network-based intrusion program on the host.

Related Searches:

References

  • Photo Credit computer being attacked by bugs image by patrimonio designs from Fotolia.com

Comments

You May Also Like

Related Ads

Featured