simple-intrusion-detection-system designed to monitor network traffic and apply custom rules to detect and respond to various types of network activity.
Before you begin, ensure you have Python installed on your system. It is recommended to use a virtual environment to manage dependencies.
-
Create a virtual environment:
virtualenv venv
-
Activate the virtual environment:
source venv/bin/activate
Once the virtual environment is activated, install the required dependencies:
pip install -r requirements.txtIf you intend to use the alert feature, you'll need to configure the alert endpoint in "rule.py"
webhook_url = 'https://your-alert-endpoint.com'
Rules determine how the IDS will react to different types of network traffic. Customize the "rules.txt" file to define your detection logic.
protocol src_ip:src_port -> dst_ip:dst_port action message
python IDS_app.py