Content deleted Content added
m moved Protocol-based intrusion detection System to Protocol-based intrusion detection system: decapitalize "system" |
cleanup; {{wikify}} |
||
Line 1:
{{wikify}}
A '''Protocol-based Intrusion Detection System (PIDS)''', is a special category of an [[Intrusion detection system|Intrusion-Detection System]], and focuses its monitoring and analysis on the protocol or protocols in use by the computing system.▼
▲A '''
== Overview ==
Line 7 ⟶ 9:
A typical place for a PIDS would at the front end of a web server monitoring the HTTP (or HTTPS) protocol stream and would understand the HTTP protocol relative to the web server/system it is trying to protect.
Where HTTPS is in use then this system would need to reside in the "shim" or interface between where HTTPS is un-encrypted and immediately prior to it entering the Web
=== Monitoring dynamic behavior ===
Line 15 ⟶ 17:
==See also==
* [[Intrusion detection system]] (IDS)
* [[
* [[Host-based intrusion detection system]] (HIDS)
* [[Application
* [[Tripwire (software)]] - a pioneering HIDS
* [[Trusted Computing Group]]
|