<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: What is Difference between Intrusion Detection System and Intrusion Prevention System?</title>
	<atom:link href="http://www.bestinternetsecurity.net/409/what-is-difference-between-intrusion-detection-system-and-intrusion-prevention-system.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.bestinternetsecurity.net/409/what-is-difference-between-intrusion-detection-system-and-intrusion-prevention-system.html</link>
	<description>Information Security Resources</description>
	<lastBuildDate>Mon, 18 May 2009 20:11:04 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Damen</title>
		<link>http://www.bestinternetsecurity.net/409/what-is-difference-between-intrusion-detection-system-and-intrusion-prevention-system.html/comment-page-1#comment-15777</link>
		<dc:creator>Damen</dc:creator>
		<pubDate>Sat, 09 May 2009 19:58:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.bestinternetsecurity.net/?p=409#comment-15777</guid>
		<description>Some people criticize that IPS has an inherent problem of automatic response to suspicious attack signals. This automatic response action can in turn  be used by hackers to trigger incorrect but damaging action by the IPS. 

For example, it can initiate an IPS to stop the connection of an active and normal port in a network hub by sending some traffic pattern that triggers the IPS&#039;s monitoring system to response by shutting down the port. But actually, the port is running normally and the hacker simply wants the IPS to do this to achieve Denial of Service (DOS) attack to that port.

Damen</description>
		<content:encoded><![CDATA[<p>Some people criticize that IPS has an inherent problem of automatic response to suspicious attack signals. This automatic response action can in turn  be used by hackers to trigger incorrect but damaging action by the IPS. </p>
<p>For example, it can initiate an IPS to stop the connection of an active and normal port in a network hub by sending some traffic pattern that triggers the IPS&#8217;s monitoring system to response by shutting down the port. But actually, the port is running normally and the hacker simply wants the IPS to do this to achieve Denial of Service (DOS) attack to that port.</p>
<p>Damen</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lukebibby</title>
		<link>http://www.bestinternetsecurity.net/409/what-is-difference-between-intrusion-detection-system-and-intrusion-prevention-system.html/comment-page-1#comment-15771</link>
		<dc:creator>lukebibby</dc:creator>
		<pubDate>Sat, 09 May 2009 18:15:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.bestinternetsecurity.net/?p=409#comment-15771</guid>
		<description>&lt;a href=&quot;http://coffee-bean-direct.com&quot; rel=&quot;nofollow&quot;&gt;Bulk Coffee Direct&lt;/a&gt;


The primary difference between an IDS and an IPS is that an IDS is a reactive security mechanism and an IPS is a proactive security mechanism. An IDS will attempt to attacks as they are occurring (that is, once the system has recognized that an attack is occuring) and an IPS will attempt to determine whether incoming traffic is &#039;probably&#039; malicious before it is received by the intended recipient.

An IDS is easier to build; for example, an IDS can reject any traffic attempting to access &#039;/etc/passwd&#039;.
An IPS *can* be more effective; for example, an IPS can categorize traffic (in real-time) and determine whether its malicious or not, and before it received by the intended recipient.

Snort  and Cisco PIX can do these types of things, to name a few.</description>
		<content:encoded><![CDATA[<p><a href="http://coffee-bean-direct.com" rel="nofollow">Bulk Coffee Direct</a></p>
<p>The primary difference between an IDS and an IPS is that an IDS is a reactive security mechanism and an IPS is a proactive security mechanism. An IDS will attempt to attacks as they are occurring (that is, once the system has recognized that an attack is occuring) and an IPS will attempt to determine whether incoming traffic is &#8216;probably&#8217; malicious before it is received by the intended recipient.</p>
<p>An IDS is easier to build; for example, an IDS can reject any traffic attempting to access &#8216;/etc/passwd&#8217;.<br />
An IPS *can* be more effective; for example, an IPS can categorize traffic (in real-time) and determine whether its malicious or not, and before it received by the intended recipient.</p>
<p>Snort  and Cisco PIX can do these types of things, to name a few.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Malik L</title>
		<link>http://www.bestinternetsecurity.net/409/what-is-difference-between-intrusion-detection-system-and-intrusion-prevention-system.html/comment-page-1#comment-15770</link>
		<dc:creator>Malik L</dc:creator>
		<pubDate>Sat, 09 May 2009 12:32:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.bestinternetsecurity.net/?p=409#comment-15770</guid>
		<description>&lt;a href=&quot;http://coffee-bean-direct.com&quot; rel=&quot;nofollow&quot;&gt;Bulk Coffee Direct&lt;/a&gt;


Intrusion Detection Systems simply detect possible intrusions and possibly notify the administrators

Intrusion Prevention Systems will not only detect the intrusions but will take actions like terminating the connection.</description>
		<content:encoded><![CDATA[<p><a href="http://coffee-bean-direct.com" rel="nofollow">Bulk Coffee Direct</a></p>
<p>Intrusion Detection Systems simply detect possible intrusions and possibly notify the administrators</p>
<p>Intrusion Prevention Systems will not only detect the intrusions but will take actions like terminating the connection.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

