Slips (Stratosphere Linux IPS) is an endpoint behavioural intrusion detection and prevention system. It combines machine-learning models, threat-intelligence feeds and expert heuristics to identify malicious behaviour in network traffic.
The software analyses live network traffic, PCAP captures, and flow data generated by tools such as Zeek, Suricata and Argus. Slips is written in Python and uses Zeek for traffic capture and analysis, with Redis providing interprocess communication. Its active blocking functionality is available on Linux.
This is free and open source software.
Key Features
- Detects malicious network behaviour using machine-learning models.
- Combines behavioural analysis with more than 40 threat-intelligence feeds and expert heuristics.
- Processes live network traffic, PCAP files and network-flow records.
- Supports data generated by Zeek, Suricata and Argus.
- Detects targeted attacks and command-and-control communications.
- Provides adaptive TLS and HTTPS anomaly detection.
- Generates local HTML reports for investigating encrypted-traffic anomalies.
- Looks up IP addresses using external services such as VirusTotal and RiskIQ.
- Includes a web interface and an optional Kalipso text-based interface.
- Supports automated peer-to-peer sharing of indicators of compromise.
- Offers popup notifications and configurable network blocking.
- Uses a modular architecture that supports additional detection modules.
- Supports federated learning through the FEEL project.
- Runs natively or in Docker containers.
Website: github.com/stratosphereips/StratosphereLinuxIPS
Support:
Developer: Stratosphere Laboratory
License: GNU General Public License v2.0
Slips is written in Python. Learn Python with our recommended free books and free tutorials.
Related Software
| Network Intrusion Detection Systems | |
|---|---|
| Snort | Intrusion detection/prevention with real-time traffic analysis/packet logging |
| Suricata | High performance Network IDS, IPS and Network Security Monitoring engine |
| Zeek | (formerly Bro) Powerful network analysis framework |
| Maltrail | Lightweight malicious traffic detection system |
| Security Onion | Platform built by defenders for defenders |
| Kismet | Wireless intrusion detection, wireless network and device detector, and more |
| psad | Intrusion detection and log analysis with iptables |
| Sagan | Multi-threads, high performance log analysis engine |
Read our verdict in the software roundup.
Explore our comprehensive directory of recommended free and open source software. Our carefully curated collection spans every major software category.This directory is part of our ongoing series of informative articles for Linux enthusiasts. It features hundreds of detailed reviews, along with open source alternatives to proprietary solutions from major corporations such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. You’ll also find interesting projects to try, hardware coverage, free programming books and tutorials, and much more. Discovered a useful open source Linux program that we haven’t covered yet? Let us know by completing this form. |


Please read our Comment Policy before commenting.