Snort IDS and IPS Toolkit — Featuring Jay Beale and Members of the Snort Team

You probably picked up this book because you've heard of Snort as an open-source intrusion detection system. However, Snort has additional capabilities that you may not be aware of. Snort is most famous for being a full-fledged open-source network-based intrusion detection system (NIDS), but Snort is also a feature-rich packet sniffer and a useful packet logger. In addition to these three central features of Snort, Snort supports sending real-time alerts when an intrusion event is detected and can even be used as an inline "intrusion prevention system" that enables you to receive alerts in real time and in several different mediums, rather than having to continuously sit at a desk monitoring your Snort system 24 hours a day.
To help you better understand the different features and capabilities of Snort, let's look at it by analogy. Snort is like a vacuum that sucks up all items of a particular kind (in this case, packets) and allows you to do different things to them once captured. You can use Snort to watch the items as they get sucked up to see what you've captured (packet sniffer); put the items into a container for later examination (packet logger), or sort them; match the items against a list of criteria; and let you know when a matching item has gone through (NIDS). These features allow for various types of useful security analysis to be performed, including closer examination of the contents of potential attacks (from the NIDS), live traffic sampling of ongoing...