Anomaly-based detection

It is a new intrusion detection system for revealing computer and network intrusion by monitoring and classifying the usual activity as normal or abnormal. This detection is based on heuristics (or rules) rather than patterns or signatures. It has two phases: the training phase (to profile a normal behavior) and the testing phase (when the current traffic is compared with the created profile).

