What is a definition for an intrusion detection system?
An intrusion detection system (IDS) is an additional component to protect a system during operation. The IDS monitors selected aspects of the system’s behavior and raises an alarm if it observes suspicious behavior.
What are the 5 relevant aspects for an IDS?
What different approaches are there regarding Time and Resources? What are the trade-offs?
challenges, trade-offs:
What different approaches are there regarding Location and Connection? What are the trade-offs?
challenges, trade-offs:
What different approaches are there regarding Intrusion and Suspiciousness?
What different approaches are there regarding Model Complexity and Observed Data?
What different approaches are there regarding Response to an alarm?