
defense And AnAlysis teChniques 297
observe an increase. e baseline figure needs constant adjustments to
reflect legitimate increases and decreases in traffic patterns. Without
these adjustments, the IDS will generate many alerts on legitimate
traffic and waste investigative resources. reshold-based detection
does not often detect a specific threat but provides a heuristic approach
to malicious activity detection. ese events require investigation to
determine the specific issue, as they are prone to trigger on nonmali-
cious traffic.
By name, IDS suggests that such systems simply detect inbound
attempts to gain entry to a device; in reality, they ...