A packet's content (data) might not only get modified intentionally by hackers, but might also suffer from naturally-occurring transmission errors, such as the change of a bit (from 0 to 1, or from 1 to 0.)
Whether the change is due to intrusion or due to an error, the goal of an Anomaly-Based IDS is to detect that it happened and let the system, or sometimes the user, know it happened.
To detect changes to data, an IDS expects to receive and use at least one of the following along with the packet:
These notes by Miriam Briskman are licensed under CC BY-NC 4.0 and based on sources.