Skip to main content
Cloud / Google Cloud / Products / Cloud IDS - Managed Intrusion Detection for VPC Networks

Cloud IDS - Managed Intrusion Detection for VPC Networks

Cloud IDS monitors network traffic in Google Cloud and alerts you when it detects malicious activity. Detection is powered by Palo Alto Networks technologies.

Security
Pricing Model Pricing as published on the official Cloud IDS pricing page
Availability Zonal IDS endpoints; one endpoint can inspect traffic from any zone in its region
Data Sovereignty Regional deployment of IDS endpoints; see the official documentation for available regions
Reliability SLA as published by the provider SLA

What Is Cloud IDS?

Cloud IDS (Cloud Intrusion Detection System) is Google Cloud’s managed intrusion detection service. It monitors traffic in your VPC networks and alerts you when it detects malicious activity. Detection is powered by Palo Alto Networks.

Technically, Cloud IDS relies on packet mirroring: traffic is copied into a Google-managed peered network with mirrored VM instances and inspected there. The connection between your VPC network and the Google-owned network is established through private services access. The production data path itself is not affected.

Core Capabilities

  • Packet mirroring into a Google-managed network for traffic inspection
  • App-ID to identify applications irrespective of port, protocol, evasive tactic, or encryption, with weekly updates
  • Threat signatures for vulnerabilities, spyware, and exploits, updated automatically
  • Coverage of north-south and east-west traffic, including lateral movement between VMs
  • Filtered mirroring based on protocol, IP address range, or ingress and egress
  • Severity levels Critical, High, Medium, Low, and Informational with a configurable minimum level
  • Logging of threat alerts for further investigation

Typical Use Cases

Detecting lateral movement: Cloud IDS also monitors east-west traffic between VMs, making movement inside the network visible.

Compliance requirements: Regulations frequently require network intrusion detection. Cloud IDS covers that requirement as a managed service.

Incident investigation: Threat alerts are logged and can be fed into existing analysis processes.

Segmented monitoring: Filtered mirroring limits inspection to defined protocols, address ranges, or traffic directions.

Benefits

  • Managed service without your own IDS appliances
  • Detection technology from Palo Alto Networks with automatically updated signatures
  • No change to the production data path, since it works through packet mirroring
  • One IDS endpoint can inspect traffic from any zone in its region
  • Configurable severity levels and traffic filters

Working with innFactory

As a certified Google Cloud Partner, innFactory supports you with Cloud IDS:

  • Sizing: determining the number of IDS endpoints based on expected throughput
  • Network design: setting up private services access and packet mirroring in your VPC architecture
  • Policies: defining traffic filters and severity levels that match your risk profile
  • Operations: connecting threat alerts to your logging and incident response processes

Get in touch for a consultation on Cloud IDS and network security on Google Cloud.

Typical Use Cases

Detection of malicious activity in VPC networks
Monitoring of north-south and east-west traffic, including lateral movement between VMs
Compliance requirements for network intrusion detection
Investigation of threat alerts through Cloud Logging

Technical Specifications

Architecture Packet mirroring into a Google-managed peered network with mirrored VM instances, connected through private services access
Detection Palo Alto Networks technologies, including App-ID for application identification irrespective of port, protocol, evasive tactic, or encryption, plus automatically updated threat signatures for vulnerabilities, spyware, and exploits
Endpoint scope Zonal resource that can inspect traffic from any zone in its region
Severity levels Critical, High, Medium, Low, and Informational; the minimum severity level in the default signature set is configurable
Throughput Maximum 5 Gbps per IDS endpoint with spikes up to 17 Gbps; Google recommends one IDS endpoint for every 5 Gbps of throughput
Traffic selection Mirror all traffic or filtered traffic based on protocol, IP address range, or ingress and egress

Frequently Asked Questions

What is Cloud IDS?

Cloud IDS (Cloud Intrusion Detection System) monitors your networks and alerts you when it detects malicious activity. Detection is powered by Palo Alto Networks.

How does Cloud IDS work technically?

Cloud IDS mirrors network traffic into a Google-managed peered network with mirrored VM instances where the traffic is inspected. The connection between your VPC network and the Google-owned network uses private services access.

How much throughput does an IDS endpoint handle?

An IDS endpoint handles a maximum of 5 Gbps and can absorb spikes up to 17 Gbps. Google recommends one IDS endpoint for every 5 Gbps of throughput. An endpoint is a zonal resource but can inspect traffic from any zone in its region.

Which threats does Cloud IDS detect?

Cloud IDS uses App-ID to identify applications irrespective of port, protocol, evasive tactic, or encryption, together with automatically updated threat signatures for vulnerabilities, spyware, and exploits. It covers both north-south and east-west traffic, including lateral movement between VMs.

Which severity levels exist?

Cloud IDS classifies threats as Critical, High, Medium, Low, or Informational. The minimum severity level in the default signature set can be customized.

Can I limit which traffic is mirrored?

Yes. You can mirror all traffic or select filtered traffic based on protocol, IP address range, or ingress and egress direction.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.

Google Cloud Partner

innFactory is a certified Google Cloud Partner. We provide expert consulting, implementation, and managed services.

Google Cloud Partner

Ready to start with Cloud IDS - Managed Intrusion Detection for VPC Networks?

Our certified Google Cloud experts help you with architecture, integration, and optimization.

Schedule Consultation