HIDS can use various methods of detection. Heuristics or signature based are more like anti-virus products. Network behavior anomaly detection is different. It uses a baseline to compare against current behavior to see if there is something unusual happening that needs attention. Here's more information about intrusion detection systems.