Intrusion detection in computer networks: prototypes

  • McPAD (Multiple classifier Payload Anomaly Detector) is a Java-written Network Based IDS for the detection of attacks based on HTTP protocol.
  • HMM-Web (A framework to the detection of server-side web attacks) is an anomaly-based IDS for the detection of attacks against web applications. It is based on Hidden Markov Models and is able to learn without supervision and detect web attacks from a set of access log files produced by the Apache web server.