Q16Security Concepts
What distinguishes signature-based detection from behavior-based detection?
← → navigate · a answer
Community votes
Discussion · 11
B 8
Selected Answer: B
Signature-based detection and behavior-based detection are two common approaches used in cybersecurity to detect and stop attacks. The main difference between these two methods is the way they identify possible threats.
Signature-based detection uses a predefined set of rules, or signatures, to identify known patterns of malicious activity. These signatures are often based on specific traits of a known threat, such as a particular virus or malware strain. When a signature-based system detects a pattern that matches one of these predefined rules, it generates an alert or takes some other action to stop the attack.
On the other hand, behavior-based detection focuses on spotting abnormal behavior that may indicate an attack. Instead of using predefined rules or signatures, behavior-based systems analyze patterns of activity to identify anomalies that may point to an attack. For example, a behavior-based system might flag an unusual amount of network traffic from a particular device or identify a user accessing a critical system outside normal business hours.
B 4
Selected Answer: B
Instead of looking for patterns tied to specific types of attacks, behavior-based IDS solutions monitor behaviors that may be linked to attacks, increasing the chance of identifying and mitigating a malicious action before the network is compromised.
https://accedian.com/blog/what-is-the-difference-between-signature-based-and-behavior-based-ids/
4
D is correct
the signature base uses a known vulnerability table, which means a vulnerability is already known and signed as a vulnerability. In contrast, the behavior base looks through already existing data and checks whether there is abnormal behavior.
B 3
Selected Answer: B
Should be B imho
B 3
Selected Answer: B
vote for B too
D 3
Selected Answer: D
The answer is "D" and is correct. Read "B" carefully it says "Behavior-based identifies behaviors that may be linked to attacks" ---- this is not behavior based...this is almost the definition of signature based. Behavior based identifies anomalies
2
I agree the answer is B because signature-based detection is only for known threats. Known threats mean it already has rules set up and is detected based on pre-established rules.
1
d is correct
1
I think it could also be B.
B 1
Selected Answer: B
Behavior is statistical, and can use AI and ML. "Summarize" is not correct
1
B is correct.
in D, it talks about known vulnerabilities, not known threats.