Heuristic (Behavioral) based: Looks for abnormal behavior - can produce a lot of false positives.
We build a baseline of what normal network traffic looks like and all traffic is matches to that
baseline. They can at times mitigate 0day attacks. Can detect 'out of the ordinary' activity, not
just attacks. Takes much more work and skills.