SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium
A security administrator is configuring a new intrusion detection system (IDS). To minimize false positives and focus on critical threats, the administrator wants to train the IDS to recognize normal network traffic patterns. Which detection method would be most suitable for this approach?
- AAnomaly-based detection
- BSignature-based detection
- CPolicy-based detection
- DHeuristic-based detection
Show answer & explanationAnswer & explanation
Correct answer: A. Anomaly-based detection
Anomaly-based detection (also known as behavior-based) builds a baseline of normal network activity and flags anything that deviates significantly from that baseline as suspicious. This approach directly aligns with the goal of training the IDS to recognize normal traffic patterns to identify unusual activity.
Why the other options are wrong
- B. Signature-based detection relies on known attack patterns and would not identify deviations from normal traffic.
- C. Policy-based detection enforces predefined security policies, not learning normal traffic patterns.
- D. Heuristic-based detection uses rules and algorithms to identify suspicious behavior, but 'training to recognize normal' is a core tenet of anomaly-based.
Anomaly-Based IDS
An Intrusion Detection System that establishes a baseline of normal network or system behavior and identifies activity that deviates significantly from this baseline as anomalous and potentially malicious.
- Detects unknown attacks (zero-day).
- Can have higher false positive rates initially.
- Requires a learning phase to establish a baseline.
- Focuses on deviations from 'normal'.
Memory trick: Signatures are known, Anomalies are new, Heuristics are smart rules.