We will discuss security monitoring tools in another section; for now the main functions of
network-based security are to either detect a potential incident based on a set of events or
prevent a known attack.
Most network-based security devices can perform detect or protect functions in one of two
ways: signature-based or anomaly-based. Signature-based detection or prevention is similar
to AV signatures that look for known traits of a particular attack or malware. Anomaly-based
systems can make decisions based on what is expected to be “normal” on the network or per
a certain set of standards (for example, RFC), usually after a period of being installed in what
is called “learning” or “monitor” mode.