Week 3 Posting - IPS/IDS/HIDS
This week’s blog will cover week 3 for BSIT380, within this week IDS and IPS were covered on how they work and are different from each other. IPS or Intrusion Protection System will locate traffic and will use predefined rules to try to block or redirect attacks to a DMZ. With IDS or Intrusion Detection System an alert goes off and the alert is typically passed to either a log or a person, a IDS works best when manual intervention is typically required or in test environments to just get a better picture of the network. In chapter 6 host-based security was covered as well as device hardening, patch management, antivirus, anti-malware, and HIDS. With anything when it comes to changes it is a good idea to log and set a procedure for said changes.