Intrusion detection systems (IDS)
Cyber Security · Engineering
Study notes
Deploy Snort: signature rule alerts on known exploit pattern; anomaly engine flags 3AM data exfiltration as unusual. Analyst triages: true positive (block IP), false positive (tune). IPS inline blocks automatically; IDS only alerts. SIEM correlates IDS with firewall logs.