Snort
Snort - a network intrusion detection system, available under a free license.
Snort has a wide range of attack detection mechanisms and enables real-time traffic analysis and packet capture over IP / TCP / UDP / ICMP-based networks. It can analyze packet streams, search for and match suspicious content, and detect many attacks and anomalies such as buffer overflows, stealth ports scans, web service attacks, SMBs, operating system detection attempts, and more. SNORT can act as an independent sniffer, packet recorder or IDS system, or IPS - inline mode. None of these modes have any advantage over the others. The only exception is the packet recorder, which can store packets on a disk in an organized directory structure. If you configure snort.conf accordingly, this will cause the system to only record packets that match the rules specified in that file.
wiki
Comments
Post a Comment