The guardian.pl (Antony Stevens) script (see
www.snort.org) does that : It read the output of the
alert file to block the ofending IP.

open (ALERT, $alert_file) or die "open $alert_file:
# this is the same as a tail -f :)
for (;;) {
  sleep 1;
  if (seek(ALERT,0,1)){

To respond to a specific attack with a specific
action, a program could use the rules files.

>        Does Snort have the capability to respond to
>an intrusion or anomaly
>by executing another program. e.g. finger, dig,
>traceroute, tcpdump 

