if I am building classifier using SVM or NN to detect an Intrusion, am I building Signature-Based Intrusion Detection System or Anomaly-Based Intrusion Detection System?
This is anomaly based detection to my understanding, as this is the focus of my research also (SVM). The idea of anomaly-based IDS is that we hope to identify possibly malicious, but previously unknown behavior by classification based on models constructed with training data (supervised learning).