Intrusion Detection and Prevention Systems are commonly mistaken for a firewall, or as a substitute for one. In practice, they serve different purposes in a network security strategy.
A firewall functions by limiting access between networks to prevent intrusion, but it cannot detect attacks originating from within the network. When opening ports for inbound internet traffic, organizations must create exceptions through the firewall - and those exceptions are exactly what an IDPS is designed to watch.
An IDPS works differently: it evaluates a suspected intrusion once it has taken place, signals an alarm, and makes attempts to stop it. These systems identify attacks designed to bypass standard firewall filtering.
How IDP Systems Work
The technology relies on attack signature databases. Organizations configure the IDP for their specific applications, and when attackers use known signatures, the attack is stopped and logged. Success depends on maintaining large, regularly updated signature databases.
Juniper Products
DHK offers Juniper hardware IDP solutions with thousands of attack signatures. Two deployment models exist: Deep Inspection (a firewall add-on with roughly 250-500 signatures) and dedicated hardware IDP platforms for organizations needing more comprehensive protection.
