<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Ids on IT Comparison</title><link>https://comparison.metacog.co.kr/tags/ids/</link><description>Recent content in Ids on IT Comparison</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 04:19:00 +0900</lastBuildDate><atom:link href="https://comparison.metacog.co.kr/tags/ids/index.xml" rel="self" type="application/rss+xml"/><item><title>IDS vs IPS: Detecting Threats vs Blocking Them</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-ids-vs-ips-detecting-threats-vs-blocking-them/</link><pubDate>Mon, 03 Aug 2026 04:19:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-ids-vs-ips-detecting-threats-vs-blocking-them/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;An IDS and an IPS both inspect network traffic for malicious patterns, but they sit in different places and react differently once a threat is found. An IDS works &lt;strong class="kw"&gt;out-of-band&lt;/strong&gt;, watching a copy of traffic and raising alerts, while an IPS works &lt;strong class="kw"&gt;inline&lt;/strong&gt;, sitting directly in the traffic path so it can block the packets itself. The distinction matters because it determines whether a false positive causes a noisy log entry or an actual outage.&lt;/p&gt;</description></item></channel></rss>