2026-10-02

Ants and lemons

Image: Unsplash

Like soldiers on a mission, they marched across the kitchen counter of that holiday home in Croatia. Ants. They were also roaming elsewhere in the house. The owner had, very helpfully, left out a spray bottle of organic pesticide. But I didn't necessarily want the critters dead; I just wanted them to stay away.

I don't remember how or why, but I got the idea to rub the counter with half a lemon. And it worked! The other half, which I placed along their path, worked just as well as a magic shield.

At home we have ant trouble too. Fortunately not indoors, but they are undermining our garden patio. After discovering this new wonder remedy, I sent an order home from Croatia to stock up on lemons in advance – they happened to be on sale. Once home, I ran to the garden to see how much lemon juice I'd need. Not an ant in sight. Not a single one. Rather deflated, over the following weeks we worked our way through the lemons bit by bit in our daily dose of orange juice.

This whole story resurfaced recently when someone from Groningen, in an Italian restaurant in London, asked me what the word for ‘ant’ is in Limburgish (a dialect from the southernmost province). We were there with a group of fellow attendees from a security conference, and ‘naturally’ my table companions decided I should go and capture those ants in a blog post.

They thought they were helping me along with the term intrusion detection, but in hindsight their Guinness levels may have been running a bit high at that point. What I'd actually needed wasn't intrusion detection at all, but intrusion prevention. The detection had been done with our own eyes; the prevention, with lemons.

So, what do intrusion detection and intrusion prevention systems (IDS/IPS) actually do? The names give it away: one only flags things, the other also steps in. Say someone tries to log in with your user ID ten times in quick succession (a hypothetical example, since in most systems you wouldn't even get that many attempts). An IDS flags this and puts up a red flag on a screen, hoping someone from security notices it. An IPS goes a step further: because that many failed login attempts isn't normal, it assumes a break-in attempt and blocks your account. Great, you think, just give me an IPS then, I don't need an IDS anymore.

As always, though, it's more nuanced than that. Intervening comes at a price. What if it was actually you logging in, but you'd accidentally hit the caps lock key, so upper and lower case ended up reversed in the password field? An IPS would then lock out the legitimate user, while an IDS alert would instead get someone to call you and ask if something's wrong. By that time you'd probably have spotted the caps lock light, smacked yourself on the forehead, and picked up right where you left off.

You'd also want a system like this to monitor whether large amounts of data are being copied (hello, Odido). But that doesn't have to be malicious – maybe an administrator is copying data as part of a legitimate job. You wouldn't want the whole thing shut down without question. But then again, maybe you would want exactly that if such a bulk action happens at three in the morning under the account of some random person (which does raise the question of whether that should even be possible in the first place, but that's a different story).

In short, you want a combination of IDS and IPS. The market has picked up on that too, since the line between IDS and IPS is blurring; modern products come with both IDS and IPS capabilities. But if you ever come across the abbreviations, at least now you know what's behind them.

And oh yes, that (South) Limburgish word for ant: it's oamezeek (ˈɔːməˌzeːk).

 

And in the big bad world…

 

Ants and lemons

Image: Unsplash Like soldiers on a mission, they marched across the kitchen counter of that holiday home in Croatia. Ants. They were also ro...