Flood Engine; Meta Engine - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

FLOOD Engine

FLOOD Engine
The FLOOD engine defines signatures that watch for any host or network sending multiple packets to a
single host or network. For example, you can create a signature that fires when 150 or more packets per
second (of the specific type) are found going to the victim host.
There are two types of FLOOD engines: FLOOD.HOST and FLOOD.NET.
Table B-7
Table B-7
Parameter
protocol
rate
icmp-type
dst-ports
src-ports
1. An alert fires when the rate is greater than the packets per second.
2. The second number in the range must be greater than or equal to the first number.
3. The second number in the range must be greater than or equal to the first number.
Table B-8
Table B-8
Parameter
gap
peaks
protocol
rate
sampling-interval
icmp-type
1. An alert fires when the rate is greater than the packets per second.

META Engine

The META engine defines events that occur in a related manner within a sliding time interval. This
engine processes events rather than packets. As signature events are generated, the META engine
inspects them to determine if they match any or several META definitions. The META engine generates
a signature event after all requirements for the event are met.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
B-10
lists the parameters specific to the FLOOD.HOST engine:
FLOOD.HOST Engine Parameters
Description
Which kind of traffic to inspect.
Threshold number of packets per second.
Specifies the value for the ICMP header type.
Specifies the destination ports when you choose UDP protocol.
Specifies the source ports when you choose UDP protocol.
lists the parameters specific to the FLOOD.NET engine:
FLOOD.NET Engine Parameters
Description
Gap of time allowed (in seconds) for a flood signature.
Number of allowed peaks of flood traffic.
Which kind of traffic to inspect.
Threshold number of packets per second.
Interval used for sampling traffic.
Specifies the value for the ICMP header type.
Appendix B
Signature Engines
Value
ICMP
UDP
1
0 to 65535
0 to 65535
2
0 to 65535
a-b[,c-d]
3
0 to 65535
a-b[,c-d]
Value
0 to 65535
0 to 65535
ICMP
TCP
UDP
1
0 to 65535
1 to 3600
0 to 65535
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents