First page Back Continue Last page Overview Graphics

Modern Techniques


Notes:

Context Awareness – Integrate knowledge of environment to reduce false-positives.
OOB Responses – Allow non-inline IDS to have reactive capability more along the lines of an IPS. Requires integration with other devices like firewalls, switches, AD domain, etc.
Anomaly Detection – More advanced statistical analysis of the traffic patterns themselves to determine “bad” behavior. Hard in many environments.