During a network security audit, this method attempts to recognize breaches based on known attack patterns and misuse signatures. What is this method called?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- ARule-based detection is a broad description of how many tools work, not the standard name for matching known attack signatures.
- BProtocol anomaly detection flags traffic that deviates from protocol specifications, even without a known signature.
- CAnomaly detection compares activity to a baseline of normal behavior and can catch unknown attacks, unlike signature matching.
- DCorrect: signature recognition, also called misuse detection, matches traffic or events against patterns of known attacks.