What is Intrusion Detection?
An intrusion detection system monitors events and produces alerts when it finds signs of an incident or policy violation. Signature methods match known patterns. Anomaly methods find deviations from a learned or defined baseline, but a deviation is not proof of an attack and a zero-day attack is not guaranteed to be detected. An IDS detects and reports. An intrusion prevention system can also block selected activity.
Why it matters
Preventive controls do not stop every attack or misuse. Detection gives responders evidence that they can investigate before an incident causes more damage.
How it works
- Sensors collect selected network, host, identity, or application events.
- Detection logic compares the events with signatures, protocol rules, or an expected baseline.
- The system sends an alert for investigation or for a defined automated response.
Example
A network IDS sees one host scan many internal SSH ports in a short period. It alerts an analyst, who relates the source address to identity and endpoint logs.
Pomerium boundary
Pomerium authorization and access logs can record identity, request, route, decision, and denial details for protected traffic. A monitoring system can use those records as detection context. Pomerium is not an intrusion detection system.
Limits and non-claims
- Detection rules can produce false positive and false negative alerts.
- Encryption and incomplete sensor coverage can hide relevant activity.
- An alert does not block or contain an incident unless a separate response performs that action.
Evaluation checklist
- Which threat behavior should each signal detect, and at which boundary?
- What are the expected false-positive, false-negative, delay, and evasion limits?
- Who investigates the alert, contains the action, and tests sensor loss or tampering?
