Intrusion Prevention System
Also known as:IPS
Intrusion PreventionPreventionMeasures intended to stop security incidents or attacks before they occur. System: Automatically detects and blocks suspicious network traffic. Controls apply to network communicationNetwork CommunicationThe exchange of data between systems over network protocols and connections. or network accessNetwork AccessThe ability of a user, device, or workload to connect to and use network resources.. Effectiveness is achieved through restrictive rules, segmentation, continuous monitoringMonitoringThe continuous observation of systems, identities, networks, and controls for relevant changes., and coordinated response processesResponse ProcessA coordinated sequence of decisions and actions for handling security events and incidents..
How it works and where it fits
Intrusion Prevention System is a preventive, detective, or corrective security control. Its effect depends on where it sits in the architecture, which data and decisions it processes, and how it might be bypassed. A control reduces a defined risk but rarely removes it completely, so it should be combined with additional layers of protection.
Practical security relevance
Before deployment, the objective, ownership, coverage, and expected behavior should be defined. Secure defaults, controlled exceptions, logging, and periodic effectiveness tests matter more than installation alone. Operational metrics should expose both blocked or detected activity and gaps, false alerts, and effects on legitimate business processes.
Related concepts
- Host Intrusion Prevention SystemHost Intrusion Prevention SystemEndpoint system for detecting and actively blocking suspicious activities.: Endpoint system for detecting and actively blocking suspicious activities.
- Intrusion Detection SystemIntrusion Detection SystemDetects suspicious or anomalous activities on hosts or within networks.: Detects suspicious or anomalous activities on hosts or within networks.
- FirewallFirewallControls network traffic based on defined rules and security policies.: Controls network traffic based on defined rules and security policies.
- Detection EngineeringDetection EngineeringSystematic development, testing, and maintenance of rules for attack detection.: Systematic development, testing, and maintenance of rules for attack detection.