From 5b744f8e8337c8f12196405eddea5c8bf83320a2 Mon Sep 17 00:00:00 2001 From: Marco Bonetti Date: Sat, 14 Aug 2010 15:40:41 -0400 Subject: libraries/libnids: Added (E-component of NIDS) Signed-off-by: dsomero --- libraries/libnids/README | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 libraries/libnids/README (limited to 'libraries/libnids/README') diff --git a/libraries/libnids/README b/libraries/libnids/README new file mode 100644 index 0000000000..b824366fc2 --- /dev/null +++ b/libraries/libnids/README @@ -0,0 +1,11 @@ +Libnids is an implementation of an E-component of Network Intrusion Detection +System. It emulates the IP stack of Linux 2.0.x. Libnids offers IP +defragmentation, TCP stream assembly and TCP port scan detection. The most +valuable feature of libnids is reliability. A number of tests were conducted, +which proved that libnids predicts behaviour of protected Linux hosts as +closely as possible. Libnids is highly configurable in run-time and offers a +convenient interface. Currently it compiles on Linux, *BSD and Solaris. +Using libnids, one has got a convenient access to data carried by a TCP +stream, no matter how artfully obscured by an attacker. + +This requires libnet. -- cgit v1.2.3