Multi-layer inspection
The multi-layer inspection feature in Snort 3 enables you to inspect traffic across multiple protocol layers within the same session.
Snort 3 can simultaneously inspect the following layers:
-
Network layer (L3): IP addresses, fragmentation
-
Transport layer (L4): TCP or UDP ports, flags, session tracking
-
Application layer (L7): HTTP, DNS, SMTP, TLS, SIP, and others.
-
File and payload layer: File extraction, malware signatures, embedded content
Snort 3 supports decoding for a wide range of protocols. It inspects encapsulated protocols and evaluates packet headers to determine policy actions during advanced threat inspection.