Glossary · OT cybersecurity
Intrusion detection system (IDS) for OT
Also known as: OT IDS, Industrial intrusion detection
German: Intrusion Detection System (IDS) für OT
In OT cybersecurity, an intrusion detection system (IDS) monitors network traffic or host activity of industrial control systems for signs of attacks, policy violations or anomalies and raises alerts, without blocking traffic itself. OT variants understand industrial protocols and learn the normal communication patterns of a plant.
- OT security
In one sentence
An OT intrusion detection system monitors industrial networks or hosts for attacks and anomalies and raises alerts without blocking traffic.
Example
The OT IDS alerts when an unknown laptop sends a stop command to a PLC over S7 communication, a pattern never seen during the learning phase.
How it applies
- Engineering: OT IDS are usually passive: they receive a copy of traffic from a mirror port or network tap, so they do not add latency or risk to control communication. Host-based variants run on industrial PCs where allowed.
- Operation: Because OT traffic is highly regular, anomaly detection works well, but every planned change (new device, new recipe download) can cause alerts. Alerts need an owner, often a Security operations center (SOC).
- Maintenance: Many OT IDS also build a passive Asset inventory from observed traffic, which helps keep the inventory current.
- Documentation: Product documentation should describe the normal communication of a component (protocols, peers, cycle times). Integrators use this to tune the IDS and to judge whether an alert shows a real deviation.
IDS vs. IPS
An IDS only detects and alerts. An intrusion prevention system (IPS) can also block traffic, which in OT is used cautiously because a false positive can interrupt production or safety communication.