First page Back Continue Last page Overview Graphics
Modern Techniques
Context Awareness
Inline Responses
OOB Responses
Extensibility, Integration, Open APIs
Anomaly Detection
Notes:
Context Awareness – Integrate knowledge of environment to reduce false-positives.
OOB Responses – Allow non-inline IDS to have reactive capability more along the lines of an IPS. Requires integration with other devices like firewalls, switches, AD domain, etc.
Anomaly Detection – More advanced statistical analysis of the traffic patterns themselves to determine “bad” behavior. Hard in many environments.