在对网络入侵检测系统Snort构架分析的基础之上,以Internet组管理(IGMP)协议为实例,提出了对Snort系统进行扩展的方法,实现了抓包、日志记录、检测出与IGMP协议有关的入侵等功能,最后给出了具体的扩展部分和实验。
The scheme to extend Snort system to support IGMP (Internet Group Management Protocol) is presented based on the analysis of the framework of the Snort system. The extended Snort can capture packet and log, and detect the intrusion related with IGMP. Finally, the concrete extension and experiment is given.