Get started Bring yourself up to speed with our introductory content.

How does Snort's flavor of intrusion detection work?

Snort is a powerful intrusion detection tool. Learn how it leverages traffic patterns to detect security risks.

Snort is a network-centric product. As an intrusion detection system, it can inspect traffic inline or offline, and act passively or actively.

Snort mostly relies on a "known bad" or "suspected bad" approach, observing traffic for patterns that correspond to malicious or suspicious activity. When Snort detects such activity, it can alert (passive mode) or block (active mode). The first is an IDS; the second an IPS.

This was last published in January 2008

Dig Deeper on Managed network services technology

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

MicroscopeUK

SearchSecurity

SearchStorage

SearchNetworking

SearchCloudComputing

SearchDataManagement

SearchBusinessAnalytics

Close