NBAD focuses on how the network normally behaves, and flags anything unusual.
Key principle
Instead of searching for known attack signatures, NBAD:
What it detects
Why it is better than signature-based systems
Example
If a workstation that normally sends 5MB/day suddenly sends 5GB at midnight, NBAD flags it as suspicious.