What are the characteristics of anomaly based IDS?
(a) It models the normal usage of network as a noise characterization
(b) It doesn’t detect novel attacks
(c) Anything distinct from the noise is not assumed to be intrusion activity
(d) It detects based on signature
This question was addressed to me in examination.
I need to ask this question from Security topic in chapter Security of Operating System