An Intrusion Detection System (IDS) is a security technology that monitors network activity to identify suspicious patterns of behaviour.
Intrusion detection commonly encompasses network and host-based methods. Network-based IDS (NIDS) is used to log and analyse traffic flowing across a network to identify unauthorised or anomalous behaviour such as policy violations and malware. Host-based IDS (HIDS) includes file integrity monitoring, log monitoring and rootkit checking to analyse activity on individual endpoint devices.
NIDS and HIDS are passive in nature and for this reason are often deployed alongside intrusion prevention systems (IPS), such as firewalls, and SIEM, which enables IDS entries to be correlated with security events from other sources.