Analyse the Working Principle of Intrusion Detection System with Snort
Miao Fang · Computer Knowledge and Technology · 2009
Snort is a signature-based IDS (Intrusion Detection System), uses rules to check for errant packets in network. Snort has four components, most of which take plug-ins to customize Snort implementation.These components include packet capture/decoder engine, preprocessor,detection engine,output plug-ins. This paper porvides a detail introduction of Snort process and the four main components of Snort.