What are characteristics of stack based IDS?
(a) They are integrated closely with the TCP/IP stack and watch packets
(b) The host operating system logs in the audit information
(c) It is programmed to interpret a certain series of packets
(d) It models the normal usage of network as a noise characterization
I had been asked this question in unit test.
This question is from Security in chapter Security of Operating System