Skip to main content

Intrusion Detection

An intrusion detection system monitors events and produces alerts when it finds signs of an incident or policy violation.

What is Intrusion Detection?

An intrusion detection system monitors events and produces alerts when it finds signs of an incident or policy violation. Signature methods match known patterns. Anomaly methods find deviations from a learned or defined baseline, but a deviation is not proof of an attack and a zero-day attack is not guaranteed to be detected. An IDS detects and reports. An intrusion prevention system can also block selected activity.

Why it matters

Preventive controls do not stop every attack or misuse. Detection gives responders evidence that they can investigate before an incident causes more damage.

How it works

  1. Sensors collect selected network, host, identity, or application events.
  2. Detection logic compares the events with signatures, protocol rules, or an expected baseline.
  3. The system sends an alert for investigation or for a defined automated response.

Example

A network IDS sees one host scan many internal SSH ports in a short period. It alerts an analyst, who relates the source address to identity and endpoint logs.

Pomerium boundary

Pomerium authorization and access logs can record identity, request, route, decision, and denial details for protected traffic. A monitoring system can use those records as detection context. Pomerium is not an intrusion detection system.

Limits and non-claims

  • Detection rules can produce false positive and false negative alerts.
  • Encryption and incomplete sensor coverage can hide relevant activity.
  • An alert does not block or contain an incident unless a separate response performs that action.

Evaluation checklist

  • Which threat behavior should each signal detect, and at which boundary?
  • What are the expected false-positive, false-negative, delay, and evasion limits?
  • Who investigates the alert, contains the action, and tests sensor loss or tampering?

Sources and further reading

Keep learning

Security Operations and Risk

Attack Surface

An attack surface is the set of boundary points where an attacker can try to enter a system, cause an effect, or extract data.

Learn this term
Security Operations and Risk

Endpoint Security

Endpoint security is the set of controls used to manage and protect devices that access organizational data and services.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo