
340 The State of the Art in Intrusion Prevention and Detection
passing to the AP (access point) under protection directly from the wireless medium. It is not neces-
sary to directly replicate every aspect of the network. Depending on the geography of the area, it
may be possible to have one device collect information for many APs. Some positives of this system
are the following:
• Equipment diversity
• Multiple source monitoring
• No network performance impact
• Larger resources for monitoring system
• No self DoS
This implementation prioritizes the operational network performance above WIDS performance
but requires additional work to plan and ...