Cisco IPS: Anomaly detection Introduction

Introduction Cisco IPS 4240 establishes a baseline (normal traffic) and uses this baseline to check for deviation from traffic patterns to determine if there is anomaly in the network. This detection technique mainly detects worm attacks originated from host/s in the network. Worm propagated by email, instant messages and file sharing cannot be detected by … Continue reading Cisco IPS: Anomaly detection Introduction

Advertisements