answersLogoWhite

0

A The term heuristics should be used where Artificial Intelligence (AI) is used to detect intrusions. IDSs that genuinely use heuristics have been allegedly almost ready for around a decade. It is my understanding that they still aren't quite clever enough and can be trained by an attacker to ignore malicious traffic. Some IDSs use anomalies to detect intrusions, where the IDS has to learn over time what can be considered normal. As this is fairly clever some vendors will sell this as a heuristic IDS. I can think of at least one IDS that does use an AI scripting language to apply analysis to the incoming data. Rather than learning what is normal signatures can be created that look for abnormal traffic these are sometimes referred to as heuristic signatures, ie., too many repeated characters in a URL.

User Avatar

Wiki User

15y ago

Still curious? Ask our experts.

Chat with our AI personalities

FranFran
I've made my fair share of mistakes, and if I can help you avoid a few, I'd sure like to try.
Chat with Fran
BlakeBlake
As your older brother, I've been where you are—maybe not exactly, but close enough.
Chat with Blake
CoachCoach
Success isn't just about winning—it's about vision, patience, and playing the long game.
Chat with Coach

Add your answer:

Earn +20 pts
Q: What is heuristics in IDS terminology?
Write your answer...
Submit
Still have questions?
magnify glass
imp