Snort is an open source network intrusion detection system (NIDS)created by Norman Roesch. Snort is a packet sniffer that monitorsnetwork traffic in real time, scrutinizing each packet closely todetect a dangerous payload or suspicious anomalies. Snort is based on libpcap (for library packet capture), a tool thatis widely used in TCP/IP traffic sniffers and analyzers. Throughprotocol analysis and content searching and matching, Snort detectsattack methods, including denial of service, buffer overflow, CGIattacks, stealth port scans, and SMB probes. When suspicious behavioris detected, Snort sends a real-time alert to syslog, a separate"alerts" file, or to a pop-up window.