What are the drawbacks of the host based IDS?
(a) Unselective logging of messages may increase the audit burdens
(b) Selective logging runs the risk of missed attacks
(c) They are very fast to detect
(d) They have to be programmed for new patterns
I have been asked this question in an interview.
This question is from Security topic in portion Security of Operating System