Libnids


TOOLS
Win32
   New Code
   libevent
   honeyd
   Old Code
   libnids
   dsniff
   ngrep
   scanlogd
   snort
   syslog wrapper

Download
   Binary Packages
   Source Code

Resources
   Winpcap ( Mirror )
   Windump ( Mirror )
   Analyzer ( Mirror )
   Ethereal
   OpenBSD
   Deja News

Development Projects
   Development Source and Binaries

Other
   Picture Gallery
   My Resume

   
COOL LINKS
   Blake Watts WIN32 God
   Snort.org
   E-Mail Me (mike@datanerds.net) PGP Key

Powered by DataNerds.net

DESCRIPTION
Libnids is an implementation of an E-component of Network Intrusion Detection System. It emulates the IP stack of Linux 2.0.x. Libnids offers IP defragmentation, TCP stream assembly and TCP port scan detection.

The most valuable feature of libnids is reliability. A number of tests were conducted, which proved that libnids predicts behaviour of protected Linux hosts as closely as possible.

Libnids is highly configurable in run-time and offers a convenient interface. Currently it compiles on Linux glibc systems, *BSD, Solaris and WIN32!.

Using libnids, one has got a convinient access to data carried by a TCP stream, no matter how artfully obscured by an attacker. You may have a look at a sample application.

Libnids is designed by Rafal Wojtczuk.


[ Original Site ]
   
UPDATES

February 6, 2001
Updated libnids WIN32 port to the newest 1.16 version of libnids
[ Library and Source ]
August 3, 2000
Updated libnids WIN32 port to the newest 1.14 version of libnids
[ Library and Source ]
May 11, 2000
I have finished the WIN32 port of libnids. You need the winpcap NDIS driver installed to use any applications that use libnids. [ Library and Source ]