97.1k views
7 votes
What is the most common form of host-based IDS that employs signature or pattern-matching detection methods

User Gotcha
by
4.5k points

1 Answer

4 votes

The two primary methods of detection are signature-based and anomaly-based. Any type of IDS (HIDS or NIDS) can detect attacks based on signatures, anomalies, or both. The HIDS monitors the network traffic reaching its NIC, and the NIDS monitors the traffic on the network.

User Turkhan Badalov
by
4.5k points