Skip to content
Up To Date Time

Up To Date Time

  • Home
  • Sports
  • cryptocurrency
  • Technology
  • Virtual Reality
  • Education Law
  • More
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
  • Toggle search form
How IDS, IPS Detects Malicious Traffic: True/False ? – HyperHCI.com

How IDS, IPS Detects Malicious Traffic: True/False ? – HyperHCI.com

Posted on November 30, 2024 By rehan.rafique No Comments on How IDS, IPS Detects Malicious Traffic: True/False ? – HyperHCI.com

It is very confusing that how IDS (Intrusion Detective System) and IPS (Intrusion Preventive System) detects malicious traffic in the network and generates true positive, true negative, false positive and false negative alerts.

There are FOUR type of IDS, IPS events: TWO is expected and other TWO is not expected:

  • True Positive
  • True Negative
  • False Positive
  • False Negative

Example: To understand TRUE / FALSE with Binary Value

Let’s try to understand all four types of IDS, IPS traffic events to make it simple let’s assume:

Traffic is Predicted as:
(0) “Positive” means = Malicious Traffic denotes by “1”
(1) “Negative” means = Normal Traffic denotes by “0”

Real / Actual traffic result as TRUE / FALSE
(1) TRUE denotes by “1”
(0) FALSE denotes by “0”

Do Predicted events and Real Result mapping with 1 and 0

Let understand with example below:

  • Expected Result – Good RESULT
    • True Positive [1 = 1] –> Malicious Traffic Attack TRUE, Alert Generated.!
    • True Negative [1=0] –> No Malicious Traffic and No Alert
  • Unexpected Result – BAD RESULT
    • False Positive[0=1] –> No Malicious Traffic, But Generated False Alert
    • False Negative[0=0] –> Malicious Traffic Attack TRUE, But No Alert Generated.!

The goal of IDS, IPS is to have only TRUE POSITIVE and TRUE NEGATIVEs. but most IDS, IPS have FALSE POSITIVE and FALSE NEGATIVE as well.

Expected IDS, IPS results are [Good Result]

IDS, IPS are designed to product followings TWO results which is considered good result and other than of this will be considered BAD result which is not acceptable.

TRUE POSITIVE [1 =1]: IDS, IPS software/device predicts network traffic as “Malicious Traffic {1)” and post analysis resulted value is TRUE (1) – IDS, IPS generates Attack Alert.

Summary: Predicted Malicious traffic (1) come, and post analysis resulted TRUE (1) Formula is [1 = 1: Attack is happening (TRUE)]

TRUE NEGATIVE [1=0]: IDS, IPS software/device predicts network traffic as “Malicious Traffic {1)” and post analysis resulted value is FALSE (0) – IDS, IPS generates no Alert.

Summary: Predicted Malicious traffic (1) come, and post analysis resulted FALSE (0) Formula is [1 = 0: No Attack is happening (FALSE)]

Unexpected IDS, IPS results are [BAD Result]

IDS, IPS is not designed for following TWO results and consider BAD result and unexpected / unwanted results which is waste of resources and dangerous to any organization to get it.

FALSE POSITVE [0=1]: IDS, IPS software/device predicts network traffic as “Malicious Traffic {1)” and post analysis resulted value is FALSE (0) means it is Normal Traffic but detected as Attack. IDS, IPS generates False Attack Alert.

Summary: Predicted Malicious traffic (1) come, and post analysis resulted FALSE (0) Formula is [0 = 1: Attack is not happening (FALSE) but detects as Attack]

Impact: it is waste of time and resources as SOC team spends time investigating non-malicious events.

FALSE NEGATIVE [0=0]: IDS, IPS software/device predicts network traffic as “Normal Traffic {0)” and post analysis resulted value is FALSE (0) – IDS, IPS generates no Alert.

Summary: Predicted Normal traffic (0) come, and post analysis resulted FALSE (0) Formula is [0 = 0: Attack is happening but does not detect as Attack]

Impact: it is arguably the worst-case / dangerous scenario where IDS, IPS is actually failed to neither prevented nor detected actual malicious traffic / attack.

Hopefully, IDS, IPS detects malicious traffic and generates alerts i.e Tue Positive, True Negative, False Positive, False Negative concept is clear to all.!

Thanks to being with HyperHCI Tech Blog to stay tuned and keep learning till last breath.!

Related

Technology

Post navigation

Previous Post: Tears of Joy by Giemel Magramo, Now a 2-Time OPBF Title Holder
Next Post: Prepare to Land a Position in IT With This CompTIA Training Bundle

More Related Articles

What Can Small Businesses Do to Help Prevent a Cyber Attack? – Inner PC Computer Solutions What Can Small Businesses Do to Help Prevent a Cyber Attack? – Inner PC Computer Solutions Technology
Talks to Watch: Figma’s Config 2024 Talks to Watch: Figma’s Config 2024 Technology
Most Advance Aliens Technology Part Most Advance Aliens Technology Part Technology
AI crawler wars threaten to make the web more closed for everyone AI crawler wars threaten to make the web more closed for everyone Technology
Amazon suffers a defeat as judge allows FTC antitrust case to move forward Amazon suffers a defeat as judge allows FTC antitrust case to move forward Technology
iPhone 16 Pro / Max Voice Memos Get Layered Recordings iPhone 16 Pro / Max Voice Memos Get Layered Recordings Technology

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • How to go from a prompt to a geo-location guessing app in minutes
  • Coresky Airdrop Guide | How To Be Eligible?
  • My interview with Play For Dream about their headset, Android XR, enterprise licensing, China, and more!
  • Sister-led social commerce startup Nectar lands $10.6M, reveals more about marketing tech
  • England vs India Test series gets a new name

Categories

  • cryptocurrency
  • Education Law
  • Sports
  • Technology
  • Virtual Reality

Copyright © 2025 Up To Date Time.

Powered by PressBook Blog WordPress theme