Glossary · OT cybersecurity
Network intrusion detection system (NIDS)
Also known as: NIDS, Network IDS
German: Netzwerk-Intrusion-Detection-System (NIDS)
In network security, a network intrusion detection system (NIDS) is an intrusion detection system that analyzes traffic on network segments, from mirror ports or taps, to detect known attack signatures, protocol misuse and anomalous communication.
- OT security
In one sentence
A network intrusion detection system (NIDS) analyzes traffic on network segments to detect attack signatures, protocol misuse and anomalies.
Example
A NIDS sensor connected to the mirror port of the cell switch detects a port scan coming from a maintenance laptop and reports it to the SIEM.
How it applies
- Engineering: Sensor placement decides what a NIDS sees. In OT, sensors typically watch conduits between zones and traffic to critical controllers. Encrypted traffic limits content inspection, which is a trade-off with secure protocols.
- Operation: Signature-based detection finds known attacks; anomaly detection finds deviations from the learned baseline. OT networks benefit from both.
- Maintenance: Signatures and baselines need updates after plant changes. Record planned changes so that analysts can separate them from real anomalies.
- Documentation: Network documentation should include where sensors are connected, which segments are covered and which are not. Product documentation that lists normal protocols and communication partners helps tune the NIDS.
NIDS vs. host-based IDS
A NIDS observes traffic between devices without running on them. A host-based IDS (HIDS) runs on a device, such as an industrial PC, and monitors files, processes and logs there, which often requires vendor approval in OT.