Snortthenetwork模式 | 企业管理 2022-09-21 150 0star收藏 版权: . 保留作者信息 . 禁止商业使用 . 禁止修改作品

(Snort User Manual Chapter 1 Snort Introduction Snort has three working modes: sniffer, packet recorder, network intrusion/intrusion detection system. Sniffer mode simply reads packets from the network and displays them on the terminal as a continuous stream. Packet recorder mode records packets to hard disk. The network intrusion/intrusion detection mode is the most complex and configurable. We can let snort analyze the network data flow to match some rules defined by the user, and take certain actions according to the detection results. Sniffer The so-called sniffer mode is where snort reads packets from the network and displays them on your console. First, let's start with the most basic usage. If you just want to print TCP/IP information on the screen, just type the following command:
Snort Chinese Manual.htm


上一篇:securing unix step step 250