Intrusion Detection System and Its Performance Evaluation |
All methods of intrusiondetection (ID) involve the gathering and analysis ofinformation from various areas within a computer or network to identifypossible threats posed by hackersand crackersinside or outside the organization. Host-based and network-based ID systemshave their respective advantages and limitations. The most effective protectionfor a proprietary network is provided by a combination of both technologies. Hostintrusion detection systems (HIDS) and network intrusion detection systems(NIDS) are methods of security management for computers and networks.In HIDS, anti-threat applications such as firewalls, antivirussoftware and spyware-detectionprograms are installed on every network computer that has two-way access to theoutside environment such as the Internet.In NIDS, anti-threat software is installed only at specific points suchas serversthat interface between the outside environment and the network segment to beprotected.