IDS mailing list archives

How do behavioral/anomaly detection systems learn?


From: "Sasha Romanosky" <sasha_romanosky () yahoo com>
Date: Wed, 4 Feb 2004 22:18:16 -0800


Greetings, 

In regards to "behavioral" or "anomaly" detection systems vs. pure
signature-based detection systems, I'm trying to understand how these
behavioral technologies differentiate "good" traffic from "bad" traffic.
I don't want to get into which is better, because they both have their
place, of course. What I'm trying to understand is how these behavioral
systems work, or "learn". 

I have seen that this technique is not unique to intrusion detection
systems, but also appears in application firewalls (e.g. Teros) and
email virus scanners (e.g. using bayesian filtering). 

With some products, I see that you configure them with specific rules,
tailored to your particular environment, and with other products, you
just point it to the network and it creates a profile all by itself. 

Does this simply amount to another form of signature system, just with
more intelligent signatures? Or is it more complex than this?.

Any references (whitepapers, archives, sites, etc) explaining this
learning would be most appreciated.


Cheers,
Sasha Romanosky


---------------------------------------------------------------------------
---------------------------------------------------------------------------


Current thread: