there is a sort of IDS called "static". such IDS don't catch anomalies actually, but watching flow's normality so all other (than normal) traffic assumed to be anomalous.
check out SANS reading room...
there is a sort of IDS called "static". such IDS don't catch anomalies actually, but watching flow's normality so all other (than normal) traffic assumed to be anomalous.
check out SANS reading room...