Understanding and study of intrusion detection systems for various networks and domains
Jubeen Shah · 2017
Intrusion Detection System (IDS) is a hardware instrument or a software routine that is used to analyze a network, a system, or a group of interconnected systems for spiteful commotion or chaos. IDS are primarily used to perceive such malicious activity and raise a flag or report it to the network or systems administrator. The analysis of the network or system under consideration can be done using two broad approaches - Knowledge Based Intrusion Detection (KBID), where the activity is rivaled against known signatures or specific decoration of the malware; and Anomaly Based Intrusion Detection (ABID) which predominantly uses Machine Learning (ML) practices to craft a model and then match the new comportment to the crafted model. Both KBID and ABID have their own set of advantages and disadvantages which would be discussed in this paper. This paper would also compare the understanding of existing IDS and Intrusion Prevention System for different network and domain and propose a Unified Threat Prevention Engine (UTPE) as anovel idea.