Snort is one of a light wight, powerful NIDS. It can detect many different kinds of attack behaviors, and give real-time alerts. Because Snort does not support the detection of IPv6 address prefix spoofing, this paper supplies a solution to implement the intrusion detection preprocessor plug-in and provides the detection process. The experimental result proves that the preprocessor has a higher detection ratio to the spoof of IPv6 address prefix, and it is an effective plug-in on the intrusion detection system.