Intrusion Detection Systems (IDS) monitor network traffic or system activities for malicious activity and policy violations, generating alerts when suspicious behavior is detected. Intrusion Prevention Systems (IPS) go further by actively blocking or preventing detected threats. IDS/IPS use signature-based detection (matching known patterns), anomaly-based detection (identifying deviations from normal behavior), and stateful protocol analysis. They are essential components of layered network security, working alongside firewalls and SIEM systems.
Networking