100 The State of the Art in Intrusion Prevention and Detection
4.8 CASE STUDY
The actual working of our framework can explain it in a more elaborated way. Our framework has
the capability of working in two different modes. They are as follows:
1. Production Hosts Modes
2. Honeygroups Only Mode
This exibility is provided for two purposes. There will be some cases in which an organization
may want to apply our framework with its existing setup. This is possible only when they will need
minimum changes to their existing network. The rst case provides the exibility of adopting this
framework without modication to a production network and the hosts inside it. Changing produc-
tion server congurations and adopting a new system is very cu