I have read many papers on anomaly-based network intrusion detection. Am I correct that each of their techniques could be implemented as Snort preprocessor? If this is true, why there are no anomaly detection preprocessors available for Snort currently, despite the fact that there are many papers out there on this subject?
SPADE is no more included in snort as I learned. PHAD, by Bernhard Guillon, should be patched, not official. AnomalyDetection is of course available.
Are anomaly detection algorithms useless practically?