The authors describe the expert-system aspects of IDES (intrusion-detection expert system). A system for computer intrusion detection IDES uses two distinct approaches to detect anomalies (which could signify intrusions) in a computer system, namely, statistical and rule-based anomaly detection. In the statistical approach, recent behavior of a subject of a computer system is compared with observed behavior and any significant deviation is considered anomalous. In the rule-based approach, acceptable behaviour of a subject is captured by a set of rules which is used to identify anomalous observed behavior. The authors claim that integrating the two approaches in IDES provides for a comprehensive system for detecting intrusions as they occur.< <ETX xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">></ETX>
No takes yet. Share an insight, caveat, or question.
Lunt et al. (2003) studied this question.
Synapse has enriched 4 closely related papers on similar clinical questions. Consider them for comparative context: