Slips (Stratosphere Linux IPS) is an endpoint behavioural intrusion detection and prevention system. It combines machine-learning models, threat-intelligence feeds and expert heuristics to identify malicious behaviour in network traffic.
The software analyses live network traffic, PCAP captures, and flow data generated by tools such as Zeek, Suricata and Argus. Slips is written in Python and uses Zeek for traffic capture and analysis, with Redis providing interprocess communication. Its active blocking functionality is available on Linux.
This is free and open source software.
Key Features
- Detects malicious network behaviour using machine-learning models.
- Combines behavioural analysis with more than 40 threat-intelligence feeds and expert heuristics.
- Processes live network traffic, PCAP files and network-flow records.
- Supports data generated by Zeek, Suricata and Argus.
- Detects targeted attacks and command-and-control communications.
- Provides adaptive TLS and HTTPS anomaly detection.
- Generates local HTML reports for investigating encrypted-traffic anomalies.
- Looks up IP addresses using external services such as VirusTotal and RiskIQ.
- Includes a web interface and an optional Kalipso text-based interface.
- Supports automated peer-to-peer sharing of indicators of compromise.
- Offers popup notifications and configurable network blocking.
- Uses a modular architecture that supports additional detection modules.
- Supports federated learning through the FEEL project.
- Runs natively or in Docker containers.
Website: github.com/stratosphereips/StratosphereLinuxIPS
Support:
Developer: Stratosphere Laboratory
License: GNU General Public License v2.0
Slips is written in Python. Learn Python with our recommended free books and free tutorials.
Related Software
| Network Intrusion Detection Systems | |
|---|---|
| Snort | Intrusion detection/prevention with real-time traffic analysis/packet logging |
| Suricata | High performance Network IDS, IPS and Network Security Monitoring engine |
| Zeek | (formerly Bro) Powerful network analysis framework |
| Maltrail | Lightweight malicious traffic detection system |
| Kismet | Wireless intrusion detection, wireless network and device detector, and more |
| Slips | Intrusion detection and prevention system |
| Sagan | Multi-threads, high performance log analysis engine |
| psad | Intrusion detection and log analysis with iptables |
Read our verdict in the software roundup.
Explore our carefully curated directory of recommended free and open source software, covering every major software category.The directory forms part of our extensive collection of articles for Linux enthusiasts. It includes hundreds of detailed reviews, together with free and open source alternatives to proprietary software from companies such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. LinuxLinks also covers interesting projects worth exploring, Linux-compatible hardware, free programming books and tutorials, and much more. Know a useful free and open source Linux application that we haven’t covered? Tell us about it using our submission form. |


Please read our Comment Policy before commenting.