The growing utilization of Internet administration in the recent years has facilitated an increment in the various types of attacks. Despite the best protection measures, many attacks have been effectively done against many organization and enterprises. Anomaly detection, misuse detection are used to detect various type of attacks. Anomaly detection produce high rate of false alarms and the later one produce less number of false alarms but it is not much efficient than the previous one. In this paper we proposed a new method by combining both detection method in real time and tried to overcome the drawbacks of existing techniques. © 2015 IEEE.