Intrusion Prevention System (IPS)
Intrusion Prevention System (IPS) is a security system that analyzes network traffic inline – i.e. directly in the data path – and automatically blocks detected attack attempts. Detected are, for example, the exploitation of known vulnerabilities, protocol misuse or the communication of malware.
In contrast to the intrusion detection system (IDS), which only observes traffic and raises an alarm, an IPS actively intervenes: it discards packets, resets connections or blocks senders. Detection is based on signatures of known attacks, on deviations from normal traffic behavior and on protocol analyses. A distinction is made between network-based systems (NIPS) and host-based systems (HIPS) on individual computers; widespread open-source engines are Snort and Suricata. Because an IPS sits in the data path, carefully tuned rules are important so that false alarms do not block legitimate traffic.
Today, IPS is usually a function of next-generation firewalls or of cloud-based Firewall as a Service (FWaaS) rather than a separate device. It must be distinguished from Network Detection and Response (NDR), which analyzes traffic on a behavioral basis and is geared toward detection and investigation rather than immediate blocking. As a preventive control, the IPS is a building block of IT Security.