IDS/IPS in firewall

I would like to suggest that Comodo Firewall / Comodo Internet Security incorporate a snort like IDS/IPS system that monitors web traffic going to the device for known attacks. An IPS option could be present to block attacks also rather than just alerting to them.

The IDS/IPS system could also monitor outgoing data too for traffic characteristic of malware/APT’s, such as beaconing, phoning home, communication to known C2 servers/botnets, etc.

A HIPS is already present when using the Proactive Security configuration. Comodo promised that this year will bring noticeable development for Viruscope behaviour blocker. In CCAV a Viruscope recogniser is able of catching keyloggers. Who know what Viruscope may bring.

I think richard means IDS/IPS as in network packets inspection rather than the type of HIPS CIS is already using. I don’t think HIPS monitors network packets at all(?) and wonder if Viruscope would analyze the network packets(?), IDS/IPS is more the job of the network firewall.

There may be some Babylonic confusion on what is what here. 88) I went to Wikipedia which states:

IDS can be apparently both Network based and host based.

But then the Wikipedia article about IPS states:

Yuck, too much language that overlaps… :wink:

All I do know is that the network based IDS functions from CIS were removed years ago. Let’s see what might slip back in through the door or Viruscope.

They have this sitting at the gateway level with Comodo’s Korugan product. This is based off SNORT and other floss software packages along side some of their own proprietary software.