Abstract:A rule-based distributed intrusion detection system NetNumen is presented in Linux in this paper. Compared with the existing network-based intrusion detection system, NetNumen combines anomaly detections (detecting the anomaly frequency of packets?arriving) with signature detections (detecting the immanent characters of specialized attack and attack instrument), which improves the detection effect of the attack of DoS (denial of service)and DdoS (distributed denial of service) dramatically.