摘要
Snort是基于特征检测的IDS(Intrusion Detection System),使用规则的定义来检查网络中有问题的数据包。Snort主要由四个软件模块组成,这些模块使用插件模式和Snort结合,扩展起来非常方便。这四个主要部件包括包捕获/解码引擎、预处理器、检测引擎、输出插件。主要介绍了Snort的处理过程以及Snort的四个主要部件的工作原理。
Snort is a signature-based IDS (Intrusion Detection System), uses rules to check for errant packets in network. Snort has four components, most of which take plug-ins to customize Snort implementation.These components include packet capture/decoder engine, preprocessor,detection engine,output plug-ins. This paper porvides a detail introduction of Snort process and the four main components of Snort.
作者
晏金
苗放
YAN Jin, MIAO Fang (College of Information Engineering, Chengdu University of Technology, Chengdu 610059, China)
出处
《电脑知识与技术》
2009年第9期7105-7107,共3页
Computer Knowledge and Technology