Due to the increasingly complex network environment, wind farm power monitoring systems are more and more likely to be exposed to vulnerabilities. Intrusion detection, as an important supplement to firewalls, can detect anomalies and effectively defend against network attacks. In this paper, a normal behavior feature model is constructed, and then rules are configured for Snort3. Finally, a Snort3-based wind farm behavioral characteristic inspector is designed based on the normal behavioral characteristic model and Snort3 rule configuration to detect unknown anomalous messages. The ability of the inspector to extract behavioral characteristics and detect anomalous messages was verified through experiments. The results show that the inspector can effectively detect data tampering attacks and man-in-the-middle attacks with reasonableness and effectiveness.