Application protocol-based intrusion detection system: Difference between revisions

Content deleted Content added
Simmondp (talk | contribs)
No edit summary
 
CmdrObot (talk | contribs)
m sp: ofen→often
Line 10:
As a basic level an APIDS would look for, and enforce the correct (legal) use of the protocol.
 
However at a more advanced level the APIDS can learn, be taught or even reduce what it ofenoften an infinite protocol set, to an acceptable understanding of the sub-set of that application protocol that is used by the application being monitored/protected.
 
Thus, an APIDS, correctly configured, will allow an application to be "fingerprinted", thus should that application be subverted or changed, so will the fingerprint change.