What is a difference between host-based intrusion detection systems (HIDS) and network based intrusion detection systems (NIDS)?

What is a difference between host-based intrusion detection systems (HIDS) and network
based intrusion detection systems (NIDS)?

What is a difference between host-based intrusion detection systems (HIDS) and network
based intrusion detection systems (NIDS)?

A.
NIDS are usually a more expensive solution to implement compared to HIDS.

B.
Attempts to install Trojans or backdoors cannot be monitored by a HIDS whereas NIDS
can monitor and stop such intrusion events.

C.
NIDS are standalone hardware appliances that include network intrusion detection
capabilities whereas HIDS consist of software agents installed on individual computers
within the system.

D.
HIDS requires less administration and training compared to NIDS.



Leave a Reply 2

Your email address will not be published. Required fields are marked *


Q 

Q 

Techopedia explains Host-based Intrusion Detection System (HIDS)

An intrusion detection system (IDS) is a software application that analyzes a network for malicious activities or policy violations and forwards a report to the management. An IDS is used to make security personnel aware of packets entering and leaving the monitored network. There are two general types of systems: a host-based IDS (HIDS) and a network-based IDS (NIDS) .

A NIDS is often a standalone hardware appliance that includes network detection capabilities. It will usually consist of hardware sensors located at various points along the network. It may also consist of software that is installed on various computers connected along the network. The NIDS analyzes data packets both inbound and outbound and offer real-time detection.

A HIDS analyzes the traffic to and from the specific computer on which the intrusion detection software is installed. A host-based system also has the ability to monitor key system files and any attempt to overwrite these files.

However, depending on the size of the network, either HIDS or NIDS is deployed. For instance, if the size of the network is small, then NIDS is usually cheaper to implement and it requires less administration and training than HIDS. However, a HIDS is generally more versatile than a NIDS.