IDS'Architecture and Classification for IDS Classification of IDS -On the basis of detection techniques: Misuse detection(signature-based):high detection rate high false negative rate,low false positive rate Anomaly detection:low detection rate,high false positive rate On the basis of data input ●HIDS ●NIDS ●Hybrid IDS
IDS’ Architecture and Classification for IDS ⚫ Classification of IDS – On the basis of detection techniques: ⚫ Misuse detection (signature-based): high detection rate high false negative rate, low false positive rate ⚫ Anomaly detection: low detection rate, high false positive rate – On the basis of data input ⚫ HIDS ⚫ NIDS ⚫ Hybrid IDS
Intrusion Detection Techniques ●Misuse detection Method based on Expert system(P-BEST) Firstly,according to experiment,creating knowledge base (attack signature base) Secondly,updating knowledge by using learning and adaptive capacity For example: EMERALD,eXpert-BSM(SRl-international developed)
Intrusion Detection Techniques ⚫ Misuse detection – Method based on Expert system (P-BEST) Firstly, according to experiment, creating knowledge base (attack signature base) Secondly, updating knowledge by using learning and adaptive capacity For example: EMERALD, eXpert-BSM (SRI-international developed)