Title:
protocol-anomaly-detection-network-based-intrusio Download
Description: A taxonomy was developed by Axelsson to define the space of intrusion detection technology and classify IDSs.
The taxonomy categorizes IDSs by their detection principle and their operational aspects. The two main
categories of detection principles are signature detection and anomaly detection. The remainder of this paper
will compare the two categories of detection principles and describe a new type of anomaly detection based on
protocol standards. While the taxonomy applies to both host-based and network-based IDSs,
and more particularly protocol anomaly filters.
This is the result of research work done at Defcom Sweden, Stockholm.
To Search:
File list (Check if you may need any files):
protocol-anomaly-detection-network-based-intrusion-detection_349.pdf