An intrusion detection systems (IDS) main purpose is to monitor a resource and notify someone in the event of a specific occurrence for an appropriate response. Based on the sources of audit data, an IDS can be classified into a Host-Based Intrusion Detection System (HBIDS) or a Network-Based Intrusion Detection System (NBIDS).
In this paper we focus on NBIDS and propose a novel concept in IDSs called the NetHost-Sensor. We describe the NetHost-Sensor ability to thwart end-to-end encryption, Denial of Services (DoS) attacks, and reduces false positives. This paper presents our experimental procedures and results in designing the NetHost-Sensor.