Interesting post over at the Infosecurity blog on Anomaly Detection in which Mike looks at different approaches - and makes a key point in that anomaly detection is part of any layered defense model.
You can read plenty here about our views - as with all approaches there are different techniques being applied. For instance, we stand apart from the competition by taking a packet-based approach to detecting changes in network behavior - using neural networking. That way we are not dependent on aging signature databases and can generate fine-grained signatures in seconds.
Comments