Analysis of Snort Packet Detecting and Parsing Mechanism

Xie Lixia · 2005

At present,Snort is an open source network intrusion detection system(NIDS) attracting most attentions.Packet detection and sniffing is the most basic and important parts in the system.In this paper we present architecture of Snort system and its detection principle and mode,analyze implement methods of packet interception and packet analysis.We point out flaws in Snort and present improvement proposals as well.

Read the paper · More papers on PaperTik