A method for inline intrusion detection includes receiving a packet at a
network gateway, storing the packet, and assigning an identifier to the
packet. The method also includes transmitting a copy of the packet and
the identifier from the network gateway to an intrusion detection system
and analyzing the copy of the packet by the intrusion detection system to
determine whether the packet includes an attack signature and
communicating a reply message from the intrusion detection system to the
network gateway. The reply message includes the identifier and is
indicative of the results of the analysis. The size of the reply message
is less than the size of the packet.