Creating Custom Signatures; Sequence For Creating A Custom Signature - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 7
Defining Signatures
Exit IP log submode:
Step 5
sensor(config-sig-ip)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 6

Creating Custom Signatures

This section describes how to create custom signatures, and contains the following topics:

Sequence for Creating a Custom Signature

Use the following sequence when you create a custom signature:
Select a signature engine.
Step 1
Assign the signature identifiers:
Step 2
Step 3
Assign the engine-specific parameters.
The parameters differ for each signature engine, although there is a group of master parameters that
applies to each engine.
Step 4
Assign the alert response:
Assign the alert behavior.
Step 5
Apply the changes.
Step 6
78-16527-01
Sequence for Creating a Custom Signature, page 7-29
Example STRING.TCP Signature, page 7-30
Example SERVICE.HTTP Signature, page 7-32
Example MEG Signature, page 7-33
Signature ID
SubSignature ID
Signature name
Alert notes (optional)
User comments (optional)
Signature fidelity rating
Severity of the alert
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
Creating Custom Signatures
7-29

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the 4215 - Intrusion Detection Sys Sensor and is the answer not in the manual?

Questions and answers

Table of Contents