# BRO IDS Anomaly detection

**URL:** <https://community.zeek.org/t/bro-ids-anomaly-detection/3873>\
**Category:** Zeek\
**Created:** [October 20, 2015, 7:56am UTC](https://community.zeek.org/t/bro-ids-anomaly-detection/3873 "2015-10-20T07:56:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Syed\_Muhammad\_Ali\_Ab](https://avatars.discourse-cdn.com/v4/letter/s/87869e/32.png) [@Syed\_Muhammad\_Ali\_Ab](https://community.zeek.org/u/Syed_Muhammad_Ali_Ab)\
**Post date:** [October 20, 2015, 7:56am UTC](https://community.zeek.org/t/bro-ids-anomaly-detection/3873/1 "2015-10-20T07:56:25Z")

</div>

dear all.  
I am working in the area of Anomaly detection. I am interested in understanding the existing mechanism implemented in BRO.

Please refer me some useful material and/or research papers, especialy how it is different than SNORT.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/bro-ids-anomaly-detection/3873/2 "2022-05-06T15:43:10Z")

</div>


