Analysis,Improvement and Redevelopment of the snort

YANG Tong,QIAO Xiang-dong,ZHENG Lian-qing
DOI: https://doi.org/10.3969/j.issn.1009-3516.2008.02.021
2008-01-01
Abstract:Snort,one of the best Open Source Network Intrusion Detection Systems,is analysed in detail,in this paper,for the sake of searching network intrusion detection system.Then a solution is proposed to eliminate the redundancy of snort's rule chain.Experiments are done,which show that the solution proposed is correct and effective.Finally,on the basis of ARP technology approach,NIDS is developed with the improved snort as kernel module.Its excellent performance proves the solution to be valid once again.
What problem does this paper attempt to address?