Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
This chapter covers the following subjects:
• Identifying malicious traffic on the network
• Monitoring and managing alarms and alerts
Cisco intrusion detection systems (IDS) and intrusion prevention systems (IPS) are some of many systems used as part of a defense-in-depth approach to protecting the network against malicious traffic. Cisco has many different platforms and options for implementing an IPS/IDS system, but the basic concepts apply across all of these platforms. This chapter focuses on the concepts of IPS/IDS in general, and then the next chapter examines the implementation of IPS/IDS as a software-based IOS solution.