Quote:
But we still would have the same problems with false positives, in fact i think you could actually have more just because if the ids tests an "idea" of its own and thinks it works, then what happens if that "idea" just screwed alot of users out of vpn access?
This is exactly why my university is using Neural nets. The Neural net is able to learn what normal traffic looks like and based on what you tell it to ignore or not, will continually learn more and more to the point to where the chances of false positives are very small (in theory). The second benefit is you now have a reliable anomaly based IDS (not signature based) and have the potential to catch much more traffic than something like Snort (because they are signature based you can alter your attack to not match the signature yet still be effective). IMHO, in the next five years, this type of an approach will become the standard (in practice it will probably be a hybrid).