Please enable JavaScript.
Coggle requires JavaScript to display documents.
Detection Methodologies (IDS (Anamoly Based Detection (limitation…
Detection Methodologies
IDS
-
Anamoly Based Detection
for example, a profile of a network might show that email activity comprises an average of 13% of network bandwidth during typical workdays
profiles can be developed for many behavioral attributes like number of web pages visited by a user, number of failed login attempts for a host, level of processor usage for a host in a given period of time
has profiles that represent normal behavior of users, hosts, network connections or applications. This profile is developed by monitoring the characteristics of typical activity over the period of time.
Compares the definition of what activity is normal against observed events to identify significant deviations
-
-
-
limitation
-
-
-
often difficult for analysts to determine why the particular alert was generated and validate the alert that it is accurate and not the false positive
-