Analyzing and Creating the Rules of Snort
Zhao Su-hu · Journal of Sichuan College of Education · 2008
Snort is a network intrusion detection system based on opening source codes.It detects intrusion behavior on the basis of rules,therefore,the processing modules of the rules are the emphasis of the research.After briefly analyzing the present status,rules and chains of Snort,starting from the characters of the rules,the paper discussed several projects of creating the rules on TCP port of Netbus to improve the credibility and efficiency of the system.The final part of the paper suggested the direction of improving Snort rules.