Talk With an Expert

Protocol Anomaly Detection for Network-based Intrusion Detection

Protocol Anomaly Detection for Network-based Intrusion Detection (PDF, 1.61MB)Published: 05 Jan, 2002
Created by:
Kumar Das

A taxonomy was developed by Axelsson to define the space of intrusion detection technology and classify IDSs. The taxonomy categorizes IDSs by their detection principle and their operational aspects. The two main categories of detection principles are signature detection and anomaly detection. The remainder of this paper will compare the two categories of detection principles and describe a new type of anomaly detection based on protocol standards. While the taxonomy applies to both host-based and network-based IDSs, this paper will focus on network-based IDSs because protocol anomaly detection is unique to analyzing network traffic.