195k views
3 votes
If you were setting up an ids with the desire to detect exploits for unknown or unreleased vulnerabilities which type of ids would you use

User Lamonte
by
6.2k points

1 Answer

6 votes
For this type of situation, i would use A Behavior-based (Anomaly-based) Intrusion Detection Systems (IDS).
A Behavior-based (Anomaly-based) Intrusion Detection Systems (IDS) will create a baseline on what system activity are considerd as 'normal' or 'acceptable'. The deviation from this baseline will give the creator an alarm or notification. Because of this feature, it would be best to handle unknown or unreleased vulnerabilities
User Gnvk
by
6.6k points