Bro (http://www.bro-ids.org/) is a NIDS, with a twist. Bro supports signature analysis, and in fact can read Snort signatures. (Snort is one of the most popular NIDS available.) Bro also performs (a limited form of) anomaly detection, looking for activity that resembles an intrusion. For example, many companies use the so-called RFC 1918 private addresses