33Network Traffic Monitoring and Analysis
and location of these modules, an IDS can be classied into one of the following categories: central-
ized, hierarchical, and distributed.
2.1.2.2.2.1 Centralized IDS A centralized IDS, in principle, has only one manager responsible for
the event analysis, detection, classication, and system action. One or more monitoring modules (also
called agents) can be employed, responsible for data collecting and transmission to the central module
(manager). Under this IDS architecture model, the central module also is known as the agent-manager.
2.1.2.2.2.2 Hierarchical IDS Both hierarchical and centralized ID systems belong to the agent-
manager model category. However, the former ones allow some variation of s ...