When it comes to network anomalies, our job is protecting the organization's network from intruders. A network intrusion is a malicious activity that threatens the security of the network. Information security professionals have suggested many categorizations to classify network attacks for better study. For example, they have classified network attacks into the following:
- Infection (malware)
- Exploding (buffer overflow)
- Probing (sniffing)
- Cheating (spoofing)
- Traverse (brute-forcing)
- Concurrency (DDoS)
Attacks can also be categorized into passive and active attacks. An active attack is when the attacker has a direct effect on the network. The Defense Advanced Research Projects Agency (DARPA) has classified active attacks into four major categories, in its intrusion detection evaluation plan. The four categories are as follows:
- Denial of Service...