The majority of commercial intrusion detection systems are network-based. These IDSs detect attacks by capturing and analyzing network packets. Listening on a network segment or switch, one network-based IDS can monitor the network traffic affecting multiple hosts that are connected to the network segment, thereby protecting those hosts.
Historically, IDS started out as host-based, which is the other major type of IDS. Identity-based and signature-based are not types of IDS.