I've been reading quite some time about anomaly/behavior based IDSes for Web servers.
I understand the downsides: possible high false positives, learning phase, constant training.
My question is how popular are these systems for Web servers? It looks like most of the IDSes are signature based (most popular one that comes to my mind is mod_security).
I know this is a very broad question, I guess I am more interested in if people use them or if these kind of IDSes are still at more theoretical/academic level?