Skip to main content

DDoS Mitigation Systems

The main difference between NIPS and Mitigators would be Mitigators are designed to do one specific job - detect and mitigate against DOS/DDOS attacks and bilateral effects of worm activity and are largely rate based. NIPS are content based, designed to detect malicious traffic and drop the packet/stream. NIPS are not always necessarily good at mitigating DOS/DDOS attacks. Mitigators generally do not have the signature coverage to provide good NIPS functionality. NIPS are like IDS but in-line. Mitigators are like firewalls but designed to detect and prevent DOS attacks rather than enforce policy.


There is some overlap between Attack Mitigation System technologies and Network Intrusion Prevention Systems therefore I'd strongly suggest looking at the Network Intrusion Prevention System Page

 

Click Here For a Great DDOS Article