This dissertation discusses network security of campus network, and summarizes safety risks and threats faced by campus network at present, meanwhile, it focuses on analyzing attack & defense strategy on DOS network layer, puts forward a campus network security plan using firewall which combines network security intrusion detection system snort, analyzes functional advantages of this plan, and describes installation deployment and configuration method of network security invasion detection system based on snort in campus network environment, as well as summarizes its application effects.