Question: 2 (9 pts) Recall that the anomaly-based IDS example presented in the slides is based on file-use statistics. The expected file use percentages (the Hi
2 (9 pts) Recall that the anomaly-based IDS example presented in the slides is based on file-use statistics. The expected file use percentages (the Hi values in the Table are periodically updated, which can be viewed as a moving average). 1. Why is it necessary to update the expected file use percentages? (3pts) 1 CMPSC 443 Homework #5 2. When we update the expected file use percentages, it creates a potential avenue of attack for Trudy. How and why is this the case? (3 pts) 3. Suppose that at the time interval following the results in the second update of the table in the slides (where H0H1H2H3 are 0.10, .38, .364 and, .156 respectively), Alice's file use statistics are given by A0=0.05, A1=0.25, A2=0.25, and A3=0.45. Is this normal for Alice? (3pts) Compute the updated values of H0 through H3. (3 pts)
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
