Browse Definitions:
Definition

breach detection system (BDS)

Contributor(s): Matthew Haughn

Breach detection systems (BDS) are a category of applications and security devices designed to detect the activity of malware inside a network after a breach has occurred.

Enterprise IT uses BDS to protect against the variety of advanced threats, especially unidentified malware.  Unlike tier 1 security, such as a firewall or intrusion prevention, that scan incoming traffic, BDS focuses on malicious activity within the network it protects. It determines possible breaches by differing combinations of heuristics, traffic analysis, risk assessment, safe marked traffic, data policy understanding and violation reporting. Using these methods, BDS are able to sometimes find breaches as they occur and at other times detect breaches and side-channel attacks that had not previously been found.

BDS has 3 different deployment methods:

  • Out-of band systems scan data mirrored from port scans from a switch or network tap.
  • In-line systems are deployed between the network and WAN interface just like tier 1 firewalls and intrusion prevention systems.
  • Endpoint deployments that use a client installed on endpoint machines.

Advanced persistent threats (APT) have a number of exploits they can use on a target, depending on what types of Internet applications the target uses and likely vulnerabilities. There are such a variety of threats that it is difficult to impossible for IT to be aware of every possibility. BDS helps with finding the unknown advanced and adaptive threats. Even major websites have been hacked;  furthermore, the average successful breach lasts 16 months. On both counts, there is certainly room to cut down on damages. The use of BDS represent a shift in philosophy from the idea of preventing every intrusion to realizing that intrusions will happen and focusing on catching those intrusions sooner.

BDS need to be configured with details such as operating system, a list of approved applications, and programs allowed to connect to the Internet. An understanding of the attack surface presented by your network is crucial to setting up a successful deployment. To that end, BDS can assess risky configurations, helping IT limit the attack surface.

Data policies can affect what type of BDS is right for an organization. Some BDS in each type of deployment forward their data back to the BDS service provider to do post-processing in their own cloud. If it is critical, however, that data not go offsite, there are also BDS vendors who offer the same level of processing on premises. BDS are a tier 2 security system, sometimes considered 2nd generation intrusion detection systems (IDS).

This was last updated in November 2014

Next Steps

Comparing breach detection systems to IDSes and NGFWs.

Continue Reading About breach detection system (BDS)

Start the conversation

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

SearchCompliance

SearchSecurity

  • black hat

    Black hat refers to a hacker who breaks into a computer system or network with malicious intent.

  • copyright

    Copyright is a legal term describing ownership of control of the rights to the use and distribution of certain works of creative ...

  • keylogger (keystroke logger or system monitor)

    A keylogger, sometimes called a keystroke logger or system monitor, is a type of surveillance technology used to monitor and ...

SearchHealthIT

  • population health management (PHM)

    Population health management (PHM) is a discipline within the healthcare industry that studies and facilitates care delivery ...

  • ICD-10-PCS

    The International Classification of Diseases, 10th Revision, Procedure Coding System (ICD-10-PCS) is a U.S. cataloging system for...

  • U.S. National Library of Medicine (NLM)

    The U.S. National Library of Medicine (NLM) is the largest biomedical library in the world.

SearchDisasterRecovery

  • business continuity plan (BCP)

    A business continuity plan (BCP) is a document that consists of the critical information an organization needs to continue ...

  • call tree

    A call tree -- sometimes referred to as a phone tree -- is a telecommunications chain for notifying specific individuals of an ...

  • mass notification system (MNS)

    A mass notification system is a platform that sends one-way messages to inform employees and the public of an emergency.

SearchStorage

  • open source storage

    Open source storage is data storage software developed in a public, collaborative manner that permits the free use, distribution ...

  • CompactFlash card (CF card)

    A CompactFlash card (CF card) is a memory card format developed by SanDisk in 1994 that uses flash memory technology to store ...

  • email archiving

    Email archiving (also spelled e-mail archiving) is a systematic approach to saving and protecting the data contained in email ...

SearchSolidStateStorage

  • RRAM or ReRAM (resistive RAM)

    RRAM or ReRAM (resistive random access memory) is a form of nonvolatile storage that operates by changing the resistance of a ...

  • JEDEC

    JEDEC is a global industry group that develops open standards for microelectronics.

  • M.2 SSD

    An M.2 SSD is a solid-state drive (SSD) that conforms to a computer industry specification written for internally mounted storage...

SearchCloudStorage

  • RESTful API

    A RESTful application program interface breaks down a transaction to create a series of small modules, each of which addresses an...

  • cloud storage infrastructure

    Cloud storage infrastructure is the hardware and software framework that supports the computing requirements of a private or ...

  • Zadara VPSA and ZIOS

    Zadara Storage provides block, file or object storage with varying levels of compute and capacity through its ZIOS and VPSA ...

Close