Glossary
/
OT Security Concepts

Intrusion Detection System (IDS)

Also known as:
IDS · network intrusion detection · NIDS · OT IDS · rail IDS

An intrusion detection system monitors a network or host for signs of malicious activity or policy violations and alerts security staff. In OT, an IDS is almost always network-based and passive: it analyses a copy of the traffic without being in the data path, so it cannot interfere with the operational systems it protects.

How it works

A network IDS receives mirrored traffic from switches or taps at strategic points, such as the boundary between the control center and the field network, or inside a train's consist network. It applies a combination of methods: signatures for known attack patterns and malware, rules that encode security policy, and anomaly detection that compares traffic against a learned baseline of normal behaviour.

Alerts are enriched with context, such as which asset is involved, what it does operationally and how severe the deviation is, and forwarded to a security information and event management system or a security operations center. An OT IDS is distinguished from an intrusion prevention system, which sits inline and blocks traffic; in rail, inline blocking is generally avoided in safety-critical paths because a false positive could stop trains.

Why it matters for security

Detection is the control that rail operators can deploy most broadly without changing certified systems, which is why it features prominently in the TSA security directives, NIS2 and the monitoring requirements of IEC 62443 and IEC 63452. An IDS also produces the evidence needed to investigate incidents and to prove to regulators and assessors that security measures are working.

A generic IT or industrial IDS understands little of rail traffic and generates either noise or silence in a signaling network. Rail-specific detection, which decodes the relevant protocols and knows what normal operation looks like, is what turns an IDS from a compliance checkbox into a working control.

Related solution

Building a rail security operations center

Bringing OT visibility and rail-specific detection into a SOC workflow.

See the solution →

Related terms

Ready to protect your rail?

Our specialists will help you back on track

Talk with an Expert