The present invention relates to a network intrusion detection and
prevention system. The system includes: a signature based detecting
device; an anomaly behavior based detecting device; and a new signature
creating and verifying device disposed between the signature based
detecting device and the anomaly behavior based detecting device, wherein
if the anomaly behavior based detecting device detects
network-attack-suspicious packets, the new signature creating and
verifying device collects and searches the detected suspicious packets
for common information, and then creates a new signature on the basis of
the searched common information and at the same time, verifies whether or
not the created new signature is applicable to the signature based
detecting device, and then registers the created new signature to the
signature based detecting device if it is determined that the created new
signature is applicable.