1.

Difference between statistical anomaly detection and rule based intrusion detection

Answer»

INTRUSION DETECTION System is a Software App that CHECKS and controls networks for malicious activities/Violations of policy.

Malicious activity/Violation is normally told to an administrator/collected centrally USING a Security Information and Event Management (SIEM) system.  

SIEM System joins results from many sources and USES alarm filtering methods to differentiate threat activity from false alarms.



Discussion

No Comment Found