Snort is a well-known open source intrusion detection system,after several years of development,it has become a stable and efficient IDS.This paper mainly analyzes the basic structure of Snort and its rules,and introduces the organizational structure and rules matching process of Snort.Based on this,the update and addition of new rules are implemented which makes users define their own new intrusion detection rules flexibly.This paper can raise the scalability of Snort system and enhance the ability to protectagainst attacks of network.
Network & Computer Security