
28 The State of the Art in Intrusion Prevention and Detection
fact has motivated the ourish of research and development of anomaly-based intrusion detection
approaches.
2.1.2.1.2 Anomaly-Based Intrusion Detection
Security systems for anomaly intrusion detection, also called behavior-based intrusion detection
systems, seek to determine or create models that represent the normal or expected behavior of com-
putational systems or communication networks. An alert will be raised whenever deviations from
the expected behavior are found. It is presumed that involved system intrusion or attack activities
are parts of the subset composed of anomalous activities. ...