Enterasys Intrusion Prevention System Manual page 241

Network sensor policies and signatures guide
Hide thumbs Also See for Intrusion Prevention System:
Table of Contents

Advertisement

Table A-1 6.x to 7.0 Keyword Mapping (continued)
6.x Keyword
SNMPCONVERT
SNMPCONVERT_VER
BOSE
SNMP_AGENT_IP
SNMP_COMMUNITY
7.0 XML Attribute
NSC/SC/C/SNMPConvert
NSC/SC/C/SNMPConvert/verbose
NSC/SC/C/SNMPTrap/agent-ip
NSC/SC/C/SNMPTrap/community
Description
Provides the Network Sensor with the ability do
quick SNMP protocol decodes. The evasion
consists of obscuring the Object Identifier in an
SNMP packet. Many signature-based IDSs rely
on the Object Identifier to detect an attack, so
this evasion is important if a user is running
many SNMP signatures on Network Sensor.
The evasion works by taking the Object Identifier
and inserting NULL bytes in between the Object
Identifier. SNMPConvert strips out the invalid
NULL bytes and return a sane Object Identifier
value for Network Sensor to match against.
We will take for an example the Windows
LanManager Object Identifier, 1.3.6.1.4.1.77. A
Network Sensor signature matches this Object
Identifier, but if the SNMP evasion technique is
used, the LanManager Object Identifier becomes
1.3.06.01.04.01.077 and would successfully
evade the IDS. However, when SNMPConvert is
turned on, the obscured LanManager Object
Identifier gets converted back into 1.3.6.1.4.1.77
and correct detection will occur.
Technical Note
SNMPv1 and SNMPv2 are supported.
Identical to the same decodes as the
NSC/SC/C/SNMPConvert, except that it logs
events when certain evasions occur.
Technical Note
For details on how this evasion works, refer to
NSC/SC/C/ActiveResponse/SniperQueue.
When the Network Sensor creates an SNMP
trap, it can select a particular IP address to show
up in the SNMP record. This IP address can be
different than the interface it is sending the
SNMP traps from. This is useful if a particular IP
address is required for recognition.
Technical Note
The default is 0.0.0.0.
The SNMP community string used by the
Network Sensor when sending SNMP traps is
specified using community.
Technical Note
The default is public.
Creating Network Sensor Policies and Signatures A-47
6.x to 7.x Mappings

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the Intrusion Prevention System and is the answer not in the manual?

Table of Contents