Difference between Intrusion Detection System (IDS) and Intrusion Prevention System (IPS)

Asmaa Shaker Ashoor,Sharad Gore
DOI: https://doi.org/10.1007/978-3-642-22540-6_48
2011-01-01
Abstract:This paper discusses difference between Intrusion Detection system and intrusion Prevention System (IDS/IPS) technology in computer networks. The differences between deployment of these system in networks in which IDS are out of band in system, means it cannot sit within the network path but IPS are in-line in the system, means it can pass through in between the devices.IDS generates only alerts if anomaly traffic passes in network traffic, it would be false positive or false negative, means IDS detects only malicious activities but no action taken on those activities but IPS has feature of detection and prevention with auto or manual action taken on those detected malicious activities like drop or block or terminate the connections. Here IDS and IPS systems stability, performance and accuracy wise result are comparing in this paper.
What problem does this paper attempt to address?