The present invention is generally directed to a computer security
management system that integrates a firewall with an intrusion detection
system (IDS). In other words, the firewall and IDS of the present
invention can be designed to communicate process or status information
and packets with one another. The present invention can facilitate
centralized control of the firewall and the IDS and can increase the
speed at which packets are passed between a secured computer network and
an external network. Increased packet processing speed can be achieved in
several ways. For example, the firewall and IDS can process packets in
series, in parallel, and sometimes singularly when one of the components
is not permitted to process a packet. Alternatively, singular processing
can also be performed when one component is permitted to pass a packet to
the secured computer network without checking with the other component.