What kind of anomalies does the anomaly detection system dectect

From: Yan Zhai (yzhai@unity.ncsu.edu)
Date: 04/18/02


Date: 18 Apr 2002 13:46:05 -0000
From: Yan Zhai <yzhai@unity.ncsu.edu>
To: focus-ids@securityfocus.com


('binary' encoding is not supported, stored as-is)

Any of you guys have the experience with any
anomaly detection system like NIDES/STAT? Among
all the true alerts generated by the anomaly detection
system, how much of them are detected abnormal
activities by a intruded user account, and hou much
of them are some on going attacks?

If possible, can anyone tell me the false alarm rate of
current anomaly detection systems?

Thanks a lot!
Yan


Quantcast