Over the years, researchers and designers have used many techniques to design intrusion detection systems. The IDS for the anomaly detection should firstly learn the characteristics of normal activities and abnormal activities, Anomaly detection tries to determine whether deviation from established normal usage patterns can be flagged as intrusions . The advantage of anomaly detection is that it can detect attacks notwithstanding whether the attacks have been seen before. But the disadvantage of anomaly detection is ineffective in detecting insiders’ attacks.