Implementing IPS in the cloud
This is one of the most-asked questions when it comes to a cloud environment. Initially, one of the most famous and free IPS, Snort was used based on a mirroring approach in AWS, where an agent installed in all the EC2 instances would mirror and send the traffic to the Snort central IPS; however, this approach led to a huge spike in the usage of the system resource all the time and this is the reason why people have stopped using it.
As far as IPS in the cloud is concerned, I prefer to use a commercial offering, which seems to work much better than that of traditional open source ones.
I have spent a lot of time evaluating many of the endpoint security products that also provide the IPS functionality, among which ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access