Analysis of Snort Packet Detecting and Parsing Mechanism
Xie Lixia
Abstract
Xie Lixia
Abstract
At present,Snort is an open source network intrusion detection system(NIDS) attracting most attentions.Packet detection and sniffing is the most basic and important parts in the system.In this paper we present architecture of Snort system and its detection principle and mode,analyze implement methods of packet interception and packet analysis.We point out flaws in Snort and present improvement proposals as well.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
At present,Snort is an open source network intrusion detection system(NIDS) attracting most attentions.Packet detection and sniffing is the most basic and important parts in the system.In this paper we present architecture of Snort system and its detection principle and mode,analyze implement methods of packet interception and packet analysis.We point out flaws in Snort and present improvement proposals as well.
Key concepts: Packet analyzer, Computer science, Network packet, Intrusion detection system, Parsing, Embedded system, Sniffing, Computer network