Browse Definitions :
Definition

breach detection system (BDS)

Contributor(s): Matthew Haughn

Breach detection systems (BDS) are a category of applications and security devices designed to detect the activity of malware inside a network after a breach has occurred.

Enterprise IT uses BDS to protect against the variety of advanced threats, especially unidentified malware.  Unlike tier 1 security, such as a firewall or intrusion prevention, that scan incoming traffic, BDS focuses on malicious activity within the network it protects. It determines possible breaches by differing combinations of heuristics, traffic analysis, risk assessment, safe marked traffic, data policy understanding and violation reporting. Using these methods, BDS are able to sometimes find breaches as they occur and at other times detect breaches and side-channel attacks that had not previously been found.

BDS has 3 different deployment methods:

  • Out-of band systems scan data mirrored from port scans from a switch or network tap.
  • In-line systems are deployed between the network and WAN interface just like tier 1 firewalls and intrusion prevention systems.
  • Endpoint deployments that use a client installed on endpoint machines.

Advanced persistent threats (APT) have a number of exploits they can use on a target, depending on what types of Internet applications the target uses and likely vulnerabilities. There are such a variety of threats that it is difficult to impossible for IT to be aware of every possibility. BDS helps with finding the unknown advanced and adaptive threats. Even major websites have been hacked;  furthermore, the average successful breach lasts 16 months. On both counts, there is certainly room to cut down on damages. The use of BDS represent a shift in philosophy from the idea of preventing every intrusion to realizing that intrusions will happen and focusing on catching those intrusions sooner.

BDS need to be configured with details such as operating system, a list of approved applications, and programs allowed to connect to the Internet. An understanding of the attack surface presented by your network is crucial to setting up a successful deployment. To that end, BDS can assess risky configurations, helping IT limit the attack surface.

Data policies can affect what type of BDS is right for an organization. Some BDS in each type of deployment forward their data back to the BDS service provider to do post-processing in their own cloud. If it is critical, however, that data not go offsite, there are also BDS vendors who offer the same level of processing on premises. BDS are a tier 2 security system, sometimes considered 2nd generation intrusion detection systems (IDS).

This was last updated in November 2014

Next Steps

Comparing breach detection systems to IDSes and NGFWs.

Continue Reading About breach detection system (BDS)

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • compliance framework

    A compliance framework is a structured set of guidelines that details an organization's processes for maintaining accordance with...

  • regulatory compliance

    Regulatory compliance is an organization's adherence to laws, regulations, guidelines and specifications relevant to its business...

  • privacy compliance

    Privacy compliance is a company's accordance with established personal information protection guidelines, specifications or ...

SearchSecurity

SearchHealthIT

  • telemedicine (telehealth)

    Telemedicine is the remote delivery of healthcare services, such as health assessments or consultations, over the ...

  • Project Nightingale

    Project Nightingale is a controversial partnership between Google and Ascension, the second largest health system in the United ...

  • medical practice management (MPM) software

    Medical practice management (MPM) software is a collection of computerized services used by healthcare professionals and ...

SearchDisasterRecovery

  • crisis management plan (CMP)

    A crisis management plan (CMP) outlines how to respond to a critical situation that would negatively affect an organization's ...

  • disaster recovery (DR) test

    A disaster recovery test (DR test) is the examination of each step in a disaster recovery plan as outlined in an organization's ...

  • business continuity plan (BCP)

    A business continuity plan (BCP) is a document that consists of the critical information an organization needs to continue ...

SearchStorage

  • kilobyte (KB or Kbyte)

    A kilobyte (KB or Kbyte) is a unit of measurement for computer memory or data storage used by mathematics and computer science ...

  • megabytes per second (MBps)

    Megabytes per second (MBps) is a unit of measurement for data transfer speed to and from a computer storage device.

  • zettabyte

    A zettabyte is a unit of measurement used by technology professionals and the general public to describe a computer or other ...

Close