Systems for detecting an attack. IDSs possess one or more sensors, which listen in on the network, evaluate suspicious network traffic, and check for known attack signatures. Good systems permit the data from the sensors to be grouped, correlated and analyzed at a central location.