Rather than you spending hours digging into packets, you can set Snort to handle analysis, and have Snort alert you when there are problems; you do this by giving Snort a set of rules.
不需花大量时间研究包,可以对Snort进行设置来处理分析,并在发生问题时收到Snort的警报;这些功能是通过为Snort指定一组规则实现的。
Assessment rules that analyze and assess the alert information.
评估规则,分析和评估预警信息。
What's more, it includes rules of thumb, customizable alert and alarm thresholds, and so on.
此外,它还包含经验值、可定制警告和警告阈值等。
应用推荐