Intrusion Detection and Prevention System (IDPS)
IDPSDefinition
A network security technology that monitors network traffic and system activities for malicious behavior or policy violations, and can automatically take action to block or prevent detected threats. IDPS combines intrusion detection (IDS) capabilities that identify and alert on threats with intrusion prevention (IPS) capabilities that actively block attacks in real-time using signature-based detection, anomaly detection, and behavioral analysis.
التعريف بالعربية
تقنية أمن شبكات تراقب حركة مرور الشبكة وأنشطة النظام بحثاً عن سلوك ضار أو انتهاكات للسياسات، ويمكنها اتخاذ إجراءات تلقائية لحظر أو منع التهديدات المكتشفة. يجمع IDPS بين قدرات كشف التسلل (IDS) التي تحدد التهديدات وتنبه عنها مع قدرات منع التسلل (IPS) التي تحظر الهجمات بشكل فعال في الوقت الفعلي باستخدام الكشف القائم على التوقيع، وكشف الشذوذ، والتحليل السلوكي.
Practical Example
A Saudi government entity deploys an advanced IDPS solution to meet NCA ECC requirements (5.1 - Network Security, 6.1 - Threat and Vulnerability Management) and protect critical national infrastructure under Vision 2030 initiatives. The system monitors all network traffic entering and leaving their data center, using machine learning to detect zero-day attacks and advanced persistent threats. When suspicious lateral movement is detected from a compromised endpoint, the IDPS automatically isolates the affected segment and alerts the security operations center, preventing data exfiltration and maintaining compliance with PDPL obligations to protect personal data from unauthorized access.