What is IDS?
• Intrusion Detection System (IDS) — intrusion detection system is a software product or device designed to detect unauthorized and malicious activity on a computer network or on a separate host.
• The task of IDS is to detect the penetration of cybercriminals into the infrastructure and generate a security alert (there are no response functions, for example, blocking unwanted activity in such systems), which will be transmitted to the SIEM system for further processing.
• Threat detection systems differ from classic firewalls, since the latter rely on a set of static rules and simply restrict traffic between devices or network segments without sending notifications.