Snort is the foremost Open Source IPS (Intrusion Prevention System) in the world.
It uses a series of rules that help define malicious network activity and uses them to generate alerts or block traffic outright.
The primary uses are: as a packet sniffer, as a packet logger, or as a full-blown network IPS.
Start by installing the package:
System > Package Manager > Available Packages > Search for: snort > Click + Install.

Wait for the confirmation.

Create a free account at Snort.org, then paste your Oinkcode here:

Note: there are no updates on the system yet.

The system now has the latest rules installed:

Define the interface to monitor for suspicious or malicious activity (usually the WAN).

Define the policy.

Under Select The Rulesets, check the relevant rulesets or click Select All.
Define WAN Preprocessors.

Enable Application ID Detection and Portscan Detection.

Enable the monitoring service on the interface.

Check the activity logs.

After refining the configuration for your network and letting it run for a couple of weeks, go to Snort Interfaces > WAN Settings > Alert Settings and enable Block Offenders.