From the course: CompTIA SecurityX (CAS-005) Cert Prep

Unlock this course with a free trial

Join today to access over 24,300 courses taught by industry experts.

Host-based IDS and IPS

Host-based IDS and IPS

- Host-Based IDS and IPS is really the precursor to Endpoint Detection and Response. Early on, Host-Based IDS was pretty much vendor driven, and then Cisco kind of went into the space big time in the '00s, but now we've kind of come full circle, and the vendors are pretty heavily involved. Traditional Host-Based IDS involves monitoring, monitoring your endpoints. It does log analysis, examining those log files, for example, on your Windows systems, the application log, the system log, the security log. It was heavily signature based, so a finite set or a finite database of signatures. Anomaly based came later, where it would look for deviations in normal behavior. Basically built upon activities of using different IP addresses and different ports, those types of anomalous behaviors. And then, of course, alerting when there was suspicious activity. Host-Based IPS, which we're going to be in-line and working at a very low level of the kernel on that particular host, not only detected…

Contents