In this paper, the Snort detection of the whole process is divided into five modules : rules processing module, packet capture and decode modules, pre-processor module, the detection engine module, alarm and output module. 因此,本文把Snort的整个检测流程分为五个模块:规则处理模块,数据包捕获与解码模块,预处理器模块,检测引擎模块,报警与输出模块。