What is the difference between statistical anomaly detection and rule-based intrusion detection?
Answers
Answered by
52
Answer:
Statistical anomaly detection involves the collection of data relating to the behavior of legitimate users over a period of time. ... Typically, a count of certain event types is kept over a particular period of time.....
Answered by
22
With rule-based anomaly detection, historical audit records are analyzed to identify usage patterns and to generate automatically rules that describe those patterns. Rule-based penetration identification uses rules for identifying known penetrations or penetrations that would exploit known weaknesses.
HOPE IT HELPS
PLEASE MAKE ME BRAINLIEST ☺️
Similar questions