The OpenAppID feature
The term AppID in the word OpenAppID indicates what the module does, namely application identification. Application identification is a key feature of next-generation firewalls (NGFWs). This feature enables Snort to perform the same level of analysis as NGFWs in addition to the IPS/IDS functionality.
Awareness of the application that is associated with network traffic is valuable information. This enables the system to control and enforce policies; it also adds more context to the remaining network traffic analysis and rule matching.
There is a main difference between the OpenAppID feature and most other features of Snort. While other features are geared toward detecting badness and stopping attacks, the OpenAppID feature is, by design, not aimed at detecting attacks and exploits. Rather, this feature is designed to detect common applications so that the network administrators can detect usage and enforce policies (for example, an organization may not allow...