Network anomaly detection requires benign and infected behavior. This detection can deal with unknown worm. However, normal behavior of some applications (e.g., peer to peer protocol) is difficult to
define and handle. So, this approach has high false detection rate.