Anomaly-based IDS
When it comes to IDS, we are generally talking about two categories: host-based and network-based. But a new class of IDS has also arisen. The new category is anomaly-based. These systems work by using machine learning techniques to identify intrusions and anomalies in data. In the previous chapters, especially in Chapter 1, Introduction to Machine Learning in Pen Testing, we looked at the different models of machine learning: supervised, unsupervised, semi-supervised, and reinforcement learning. Anomaly-based IDS are also categorized into supervised and unsupervised systems, depending on the machine learning model used to detect the network intrusion. The information security community, after many years of research, has ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access