Chapter 7
Defining Signatures
Exit IP log submode:
Step 5
sensor(config-sig-ip)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 6
Creating Custom Signatures
This section describes how to create custom signatures, and contains the following topics:
•
•
•
•
Sequence for Creating a Custom Signature
Use the following sequence when you create a custom signature:
Select a signature engine.
Step 1
Assign the signature identifiers:
Step 2
•
•
•
•
•
Step 3
Assign the engine-specific parameters.
The parameters differ for each signature engine, although there is a group of master parameters that
applies to each engine.
Step 4
Assign the alert response:
•
•
Assign the alert behavior.
Step 5
Apply the changes.
Step 6
78-16527-01
Sequence for Creating a Custom Signature, page 7-29
Example STRING.TCP Signature, page 7-30
Example SERVICE.HTTP Signature, page 7-32
Example MEG Signature, page 7-33
Signature ID
SubSignature ID
Signature name
Alert notes (optional)
User comments (optional)
Signature fidelity rating
Severity of the alert
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
Creating Custom Signatures
7-29
Need help?
Do you have a question about the 4215 - Intrusion Detection Sys Sensor and is the answer not in the manual?
Questions and answers