A The term heuristics should be used where Artificial Intelligence (AI) is used to detect intrusions. IDSs that genuinely use heuristics have been allegedly almost ready for around a decade. It is my understanding that they still aren't quite clever enough and can be trained by an attacker to ignore malicious traffic. Some IDSs use anomalies to detect intrusions, where the IDS has to learn over time what can be considered normal. As this is fairly clever some vendors will sell this as a heuristic IDS. I can think of at least one IDS that does use an AI scripting language to apply analysis to the incoming data. Rather than learning what is normal signatures can be created that look for abnormal traffic these are sometimes referred to as heuristic signatures, ie., too many repeated characters in a URL.
Chat with our AI personalities