    A Critical Analysis of Payload Anomaly-Based Intrusion Detection Systems

    Examining payload content is an important aspect of network security, particularly in today\u27s volatile computing environment. An Intrusion Detection System (IDS) that simply analyzes packet header information cannot adequately secure a network from malicious attacks. The alternative is to perform deep-packet analysis using n-gram language parsing and neural network technology. Self Organizing Map (SOM), PAYL over Self-Organizing Maps for Intrusion Detection (POSEIDON), Anomalous Payload-based Network Intrusion Detection (PAYL), and Anagram are next-generation unsupervised payload anomaly-based IDSs. This study examines the efficacy of each system using the design-science research methodology. A collection of quantitative data and qualitative features exposes their strengths and weaknesses

    Intrusion prevention systems: How do they prevent intrusion?

    Intrusion Prevention Systems (IPS) are the latest in a line of products created to counter network attacks. This thesis has explored the history of products manufactured to protect network systems from attacks. An experiment was conducted to find out what an attack on a systems looked like and to gauge the success of current IPS software. Results indicated that current IPS were reasonably effective and that the methodology of attacking a system was predictable, allowing administrators scope for putting methods in place to counter attacks. 