Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Intrusion detection system (IDS) for OT

Also known as: OT IDS, Industrial intrusion detection

German: Intrusion Detection System (IDS) für OT

In OT cybersecurity, an intrusion detection system (IDS) monitors network traffic or host activity of industrial control systems for signs of attacks, policy violations or anomalies and raises alerts, without blocking traffic itself. OT variants understand industrial protocols and learn the normal communication patterns of a plant.

  • OT security

In one sentence

An OT intrusion detection system monitors industrial networks or hosts for attacks and anomalies and raises alerts without blocking traffic.

Example

The OT IDS alerts when an unknown laptop sends a stop command to a PLC over S7 communication, a pattern never seen during the learning phase.

How it applies

  • Engineering: OT IDS are usually passive: they receive a copy of traffic from a mirror port or network tap, so they do not add latency or risk to control communication. Host-based variants run on industrial PCs where allowed.
  • Operation: Because OT traffic is highly regular, anomaly detection works well, but every planned change (new device, new recipe download) can cause alerts. Alerts need an owner, often a Security operations center (SOC).
  • Maintenance: Many OT IDS also build a passive Asset inventory from observed traffic, which helps keep the inventory current.
  • Documentation: Product documentation should describe the normal communication of a component (protocols, peers, cycle times). Integrators use this to tune the IDS and to judge whether an alert shows a real deviation.

IDS vs. IPS

An IDS only detects and alerts. An intrusion prevention system (IPS) can also block traffic, which in OT is used cautiously because a false positive can interrupt production or safety communication.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on NIST SP 800-82 and industrial cybersecurity practice

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!