Signature mode
Benign packet Known attack (signature match) Novel attack (anomalous size) Flagged by sensor
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

IDS/IPS: Signature vs Anomaly Detection

An intrusion detection system inspects traffic as it flows past a sensor, deciding — per packet, in real time — whether it looks malicious. This simulator streams a mix of benign, known-attack and novel-attack packets through a 3D sensor gate and lets you switch the detector between two real strategies: signature matching, which recognizes cataloged attack patterns with high precision but is blind to anything new, and anomaly scoring, which flags statistical outliers in packet size against a learned baseline and can catch zero-days at the cost of more false alarms. Tune the sensitivity threshold and the attack mix to watch the true-positive and false-positive rates respond, then flip on IPS mode to see flagged packets actively blocked at the wire instead of merely logged.