To protect against computer attacks, firewalls are no longer sufficient today. Intrusion detection systems are able to spot threats that firewalls do not suspect.
There are several methods of analysis and monitoring
Anomaly detection system.
Signature detection system.
Hybrid system combining methods by anomalies and by signatures.
Families of intrusion detection systems
Network intrusion detection systems.
Host intrusion detection systems.
Collective intrusion detection systems.
Examples of intrusion detection systems
Network intrusion detection systems
Host intrusion detection systems
Detecting intrusions is an important element in ensuring preventive security.
But in order to manage all of the security of a company, it may be worth considering setting up a SIEM.
SIEM stands for Security Information and Event Management or management of information and security events. SIEM can be defined as real-time event collection, monitoring, correlation and analysis of events across disparate sources.
SIEMs allow:
collection
aggregation
standardization
correlation
the report
archiving
replay of events
SecureHenlo has solid experience in setting up and configuring intrusion detection and Security Information Management tools.