130 The State of the Art in Intrusion Prevention and Detection
changes to an existing system at the middleware level. Their approach embeds interval-based and
procedural-based IDS sensors and misuse-based IDS detectors in the middleware of the applications.
Valdes and Cheung develop an IDS on the supply-side of the smart grid by combining statistical
anomaly and signature detection techniques deployed in both the network and host [56]. A model-
based approach is adopted in which the network behavior is characterized using a model, and devia-
tions from the model are considered as attacks. Multiple techniques are implemented for analysis:
specication-based, change detection, and statistical anomaly detection. The IDS uses Snort for
actual detect ...