SP 800-31, NIST SPECIAL PUBLICATION: INTRUSION DETECTION SYSTEMS (NOV 2001)
SP 800-31, NIST SPECIAL PUBLICATION: INTRUSION DETECTION SYSTEMS (NOV 2001)., Intrusion detection systems (IDSs) are software or hardware systems that automate the
process of monitoring the events occurring in a computer system or network, analyzing
them for signs of security problems. As network attacks have increased in number and
severity over the past few years, intrusion detection systems have become a necessary
addition to the security infrastructure of most organizations. This guidance document is
intended as a primer in intrusion detection, developed for those who need to understand
what security goals intrusion detection mechanisms serve, how to select and configure
intrusion detection systems for their specific system and network environments, how to
manage the output of intrusion detection systems, and how to integrate intrusion detection
functions with the rest of the organizational security infrastructure. References to other
information sources are also provided for the reader who requires specialized or more
detailed advice on specific intrusion detection issues.