cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1432
Views
5
Helpful
2
Replies

IPS with Anomaly Detection

alsayed
Level 1
Level 1

Hello guys!


Anomaly-detection algorithm detectand stop zero-day threats

Does the above means that no attack may Happend when we have used the anomaly detection on the IPS?

Thanks

2 Replies 2

Scott Fringer
Cisco Employee
Cisco Employee

No, this does not mean that no attack can happen when the anomaly detection functinality is in use.  It does allow the IPS sensor to better determine the possible activity of a wormspread across your network.  The anomaly detection component lets the sensor  learn normal activity (baseline) and in turn send alerts or take dynamic response actions  for behavior that deviates from what it has learned.

  You can find out more about the IPS anomoly detection engine here:

http://www.cisco.com/en/US/docs/security/ips/6.0/configuration/guide/idm/dmAD.html#wp1184302

Thanks,

Scott

Thanks

Review Cisco Networking products for a $25 gift card