The documentation for various functions of ATA are posing some confusion on how best to classify it.
Would it be best considered an IPS or an IDS?
Because it can automatically detect certain behaviors as known malicious based on research that would lend it to an IPS. However, according to documentation, because the system has to learn about known activity, and also has to see the suspicious
activity occur before it will create an event it also seems as though it would be an IDS because the attacker would already need to be in and able to actively launch an attack for the activity to be seen and tracked.
Can someone clarify this? Or am I misunderstanding something from the documentation?
Thanks!
Dustin