An intrusion detection system watches a copy of the traffic and raises an alert. An intrusion prevention system sits in the traffic path and drops the packet. The detection engine in both is the same. The difference is placement, and placement decides the latency budget, the failure mode, and whether a mistake is a log line or an outage.
- An IDS is out of band, on a tap or mirror port
- An IPS is inline, and can take the network down
- A false positive costs a log line, or an outage
- Neither replaces a firewall, which answers a policy question
- Most organizations already own an IPS, inside the firewall
On this page
- What both intrusion systems are doing
- The difference between intrusion detection and prevention
- What intrusion prevention can actually stop
- Network based and host based, the other axis
- Firewall, IDS and IPS
- Deploying intrusion detection or prevention without regretting it
- Where people go wrong
- Comparison
- FAQ
Detection enginesWhat both intrusion systems are doing
Before the difference, the part that is identical in both intrusion systems.
IDS and IPS systems both inspect network traffic and compare what they see against a definition of malicious. Both use two detection methods, usually together, and the security they provide is only as good as those methods.
Signature based detection matches network traffic against known threat patterns: a specific exploit, a known malware beacon, a string that appears in one attack tool. Signature based detection is precise, it explains itself, and it only ever finds threats somebody has already described. New attacks pass unnoticed until a signature exists.
Anomaly based detection builds a picture of normal for the network and flags suspicious data that departs from it. It can catch malicious activity and novel attacks never seen before, and it produces far more false positives, because networks are full of unusual behavior that is entirely legitimate.
Every serious IDS and IPS runs both. The signature engine catches known threats, the anomaly engine catches the strange, and the tuning work is deciding what the second one is allowed to say out loud.
PlacementThe difference between intrusion detection and prevention
Everything that separates an IDS from an IPS comes from one decision: does the network traffic pass through the system, or past it.
An intrusion detection system, the IDS, is out of band. It receives a copy of the network traffic, from a tap or a switch mirror port. The real traffic never touches the IDS.
It can be unplugged at any moment without a packet being lost, it can be as slow as it likes, and it can hold state for hours because nothing waits on its access to the data.
An intrusion prevention system, the IPS, is inline. Every packet passes through the IPS on the way to somewhere else. That is what allows the system to drop one, and it is also what makes it a device that can take the network down, either by failing or by being wrong.
Three consequences follow, and between them they are the whole argument.
Latency budget. Intrusion detection has none, because nothing waits for it. Intrusion prevention adds time to every packet on the network and has to decide in microseconds, which limits how deeply it can inspect the data.
Failure mode. An IDS that dies stops alerting and nothing else happens. An IPS that dies either stops the network, which is fail closed, or passes everything uninspected, which is fail open. Both are choices somebody has to make deliberately and write down.
The cost of being wrong. An IDS false positive is a line in a log that somebody eventually reads. An IPS false positive is a blocked application, an angry department, and a ticket that takes an hour to trace back to a security system nobody remembers is there.
The limitsWhat intrusion prevention can actually stop
The honest version, because vendor material blurs what these systems do.
An IPS prevents only the threats it recognizes, in network data it can read, fast enough to decide before the packet leaves. Each of those three conditions removes a category of attack.
It has to recognize the threat. Novel attacks with no signature pass, unless the anomaly based engine catches them and is set to block, which almost nobody does because of the false positive cost.
It has to be able to read the traffic. Encrypted network traffic is opaque without decryption, and most traffic is encrypted. An IPS without TLS inspection sees destinations and sizes, not content, which is a real security limitation and the reason inspection appliances and privacy arguments arrive together.
It has to be fast. Some inspection is too expensive to do inline in real time. Full file reconstruction and sandbox detonation happen out of band, which is one reason an IDS still exists on networks that already run intrusion prevention.
Network and hostNetwork based and host based, the other axis
Detection and prevention is one distinction. Where the intrusion system runs is the other, and the two combine, so a product is usually named by both.
A network based IDS, the NIDS, watches traffic on a segment. The system sees everything crossing that link, from any device, including printers and cameras that will never run an agent. What it cannot see is what happens inside a host, or anything in a session it cannot decrypt.
A host based IDS, the HIDS, runs as an agent on the machine. The system watches processes, file access, registry keys and local logs for suspicious activity. It sees the attack after decryption, which is exactly the visibility a network based system loses on encrypted traffic, and it sees nothing on any device that cannot run the agent.
| System | Sees | Blind to |
|---|---|---|
| NIDS | Traffic on the segment, every device | Inside a host, encrypted payloads |
| HIDS | Processes, file access, local activity | Anything without an agent |
| NIPS | The same as NIDS, and blocks inline | The same as NIDS |
| HIPS | The same as HIDS, and blocks locally | The same as HIDS |
The two systems are complements rather than alternatives, and the reason is the encryption argument above. A network based IDS is losing visibility every year as more traffic is encrypted.
A host based system watches the same attack after the traffic has been decrypted by the application that received it. An organization running only network security sensors has a gap that grows on its own, without anybody changing anything.
Host based intrusion prevention has largely been absorbed into endpoint detection and response, which is the same idea with better tooling and an investigation workflow. If the estate runs a modern endpoint product, the host half of this is already covered and the question is only what the network half adds.
Against a firewallFirewall, IDS and IPS
These three security systems get confused constantly, and the distinction is clean.
A firewall decides whether a connection is allowed based on where it came from, where it is going, and increasingly which application it is. The firewall answers a policy question, not a threat question.
An IDS and an IPS decide whether allowed traffic is malicious. Intrusion detection and prevention inspect what the firewall let through, looking at content rather than at addresses.
In practice the three arrived in one box. A next generation firewall runs firewall policy, intrusion prevention and application awareness on one security appliance, which is why most organizations now own an IPS without ever making a separate decision about one.
That is fine, and it is worth knowing what is switched on inside it, because the intrusion prevention component is frequently in detection mode out of the box.
| Control | Question it answers | Sits |
|---|---|---|
| Firewall | Is this connection permitted | Inline |
| IDS | Is this traffic malicious | Out of band |
| IPS | Is this traffic malicious, and prevent it | Inline |
| WAF | Is this web request an attack on the application | Inline, at the app |
| NDR | What does this network normally do, and what changed | Out of band |
DeploymentDeploying intrusion detection or prevention without regretting it
The mistakes with these systems are consistent enough to list in order.
Start an IPS in detection mode. Run the system inline but alerting only for several weeks, read what it would have blocked, and turn blocking on rule group by rule group. Every organization that has skipped this has had the IDS block something important in the first week.
Decide fail open or fail closed before it happens. Not during the security incident. A retail network usually fails open, because a shop that cannot take payments is a worse outcome than uninspected data for an hour. A network holding regulated data may reasonably fail closed. What is unacceptable is finding out which one it does by accident.
Put the sensors where the network traffic actually is. A system at the internet edge sees nothing of what moves between two servers in the same subnet, and lateral movement is where a threat spends most of its time. That is the argument for internal IDS sensors, and it is usually the gap in an existing deployment.
Feed the security alerts to somebody. An IDS whose output goes to a mailbox nobody opens provides no security and full confidence, which is worse than not having one at all. Route the alerts into whatever the security team actually reads.
Keep the threat signatures current. A signature based system is only as good as its last update, and an appliance whose subscription lapsed is inspecting for last year's threats while reporting that everything is fine.
PitfallsWhere people go wrong
Treating intrusion prevention as a replacement for patching. Virtual patching, where the IPS prevents the exploit while the fix is scheduled, is genuinely useful and is a bridge rather than a destination. The vulnerability is still there when the threats arrive some other way.
Turning on every blocking rule. Modern IPS rule sets contain tens of thousands of attack signatures, many for software the network does not run. Enabling all of them costs performance and produces security alerts nobody can triage. Enable the types that match the software you actually run.
Assuming the encrypted traffic is being inspected. It usually is not. Check, because the answer changes what security the system is actually providing.
Ignoring the maintenance window problem. An inline IPS needs updates, and updating it interrupts network traffic unless the deployment is redundant. Two devices with a bypass path is the standard answer and it doubles the cost, which is the real reason many organizations run detection only.
Buying a system instead of having a process. Both an IDS and an IPS produce security findings that need a person. Without someone to read them and something to do afterward, the appliance is an expensive way to fill a compliance box.
ComparisonIntrusion detection and intrusion prevention, on what placement actually costs
| Criterion | IDS | IPS |
|---|---|---|
| Prevents an attack in progress | No | Yes |
| Can take the network down | No | Yes |
| Adds latency | None | Some, always |
| Cost of a false positive | A log line | An outage |
| Can inspect deeply and slowly | Yes | Limited by blocking latency |
| Needs a redundant path for updates | No | Yes |
| Useful without staff to read it | No | Partly |
| Sees lateral traffic if placed internally | Yes | Yes |
| Typical deployment today | An IDS sensor, or NDR | Inside the firewall |
The last row is the practical answer for most organizations. Intrusion prevention is already there inside the next generation firewall and needs tuning rather than buying. The IDS role is worth adding separately, internally, where the firewall cannot see any of the activity.
FAQFrequently asked questions
What is the main difference between IDS and IPS?
An IDS watches a copy of the network traffic and alerts. An IPS sits in the path and can drop the packet. The detection engine in both systems is the same.
Can one system do both?
Yes, and most do. An inline IPS set to alert only is behaving as an IDS, which is exactly how a new intrusion prevention deployment should start. The two are one system in two modes.
Does an IPS replace a firewall?
No. A firewall decides whether a connection is permitted. An IPS inspects the content of connections that were permitted, looking for threats. The two systems answer different security questions.
Which system should a small organization buy first?
Neither, usually. The IPS inside the firewall they already own, switched on and tuned, delivers more security than a new IDS appliance nobody has time to run.
What is signature based detection?
Matching network traffic against known attacks and their patterns. Signature based detection is precise, self explaining, and blind to any threat nobody has described yet.
What is anomaly based detection?
Building a model of normal network activity and flagging suspicious departures from it. It catches novel attacks and produces many more false positives.
Can an IPS inspect encrypted network traffic?
Only with TLS decryption, which needs certificate deployment and carries real privacy and performance costs. Without it the system sees destinations and volumes, not content, so it cannot block what is inside.
What does fail open mean?
That an inline device passes traffic uninspected if it fails, rather than stopping the network. The alternative, fail closed, keeps the traffic inspected and stops it when the device dies.
Where should IDS sensors be placed?
At the internet edge, and internally between segments. Edge only placement misses lateral movement and internal activity, which is where a threat spends most of its time.
Is intrusion prevention worth it if the network is fully encrypted?
Partly. Reputation, protocol anomalies, data volumes and destinations remain visible, and that activity catches beacons and exfiltration patterns. It will not prevent an exploit inside a session it cannot read.
How long does IDS and IPS tuning take?
Weeks, not days, and it never really stops. Plan for several weeks of alert only time before anything is set to block.
What is NDR, and how is it different from an IDS?
Network detection and response, which is anomaly based detection at network scale with an investigation workflow attached. Out of band like an IDS, aimed at activity over time rather than single packets.
Keep readingRelated concepts
Read next · Identity and access What Is MFA? Detection finds an intrusion in progress. Authentication is what makes it harder to start one. Open this next16 min- Network security · 14 min What Is a Firewall? A firewall decides whether a connection is permitted. These decide whether the permitted traffic is an attack.
- Identity and access · 13 min Zero Trust Explained Internal sensors exist because the interesting movement happens after something is already inside.
- Network security · 14 min What Is a WAF? The general purpose inspection this sits alongside, aimed at the network rather than the application.
- Operations · 13 min Patch Management, and Why the Hard Part Is Not the Patching The compensating control for the systems that stay unpatched.
- Network security · 9 min The Implicit Deny, and Why the Rule You Just Added Did Nothing Why the traffic reached it, or did not.
- Network security · 10 min Stateful vs Stateless Firewall, and Where Stateless Filtering Still Lives Why connection tracking is the base every firewall stands on, and the two ways it fails.