Enterasys Intrusion Prevention System ships with a comprehensive set of vulnerability and
exploit-based signatures. In addition, Enterasys continually provides signature updates with the
Live Update feature. The predefined signatures are organized in Master Libraries, which can be
viewed from the Signature Libraries tab in the Network Policy View.
You can assign Master Libraries directly to a virtual Network Sensor, or you can create your own
custom signatures and signature libraries and assign them to a sensor.
This chapter first presents basic information about signatures, then describes how to create
custom signature libraries and custom signatures.
For information about...
Signature Overview
Creating Custom Signature Libraries
Creating Custom Signatures
Creating Custom Event Groups
Example of Signature Creation
Signature Overview
Creating signatures that accurately identify the various attacks, probes, misuse, and other sought
data from network traffic without false positives and negatives can sometimes be deceivingly
complicated. Enterasys IPS administrators who want to produce their own signatures should have
a firm understanding of the information that can be discerned and the conclusions that can be
reached from observing network traffic. Some of the common styles of signatures and how they
are used are described in this section.
Resource-Based Signatures
The first type of signature to consider is that of usage. This signature is effective because it
assumes that any attack or probe which attempts to exploit a particular network resource uses that
resource at some time. With these signatures, there is a database of specific "bad things." When
these bad things are seen, alerts can be sent and a good understanding of the attack or probe
which was executed against us is achieved.
Creating Network Sensor Signatures
Refer to page...
Creating Network Sensor Policies and Signatures 3-1
3
3-1
3-5
3-12
3-43
3-44
Need help?
Do you have a question about the Intrusion Prevention System and is the answer not in the manual?