Configuring Signature Fidelity Rating - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 7
Defining Signatures
-----------------------------------------------
sensor(config-sig-sig-eve)#
Exit signatures submode:
Step 10
sensor(config-sig-sig-eve)# exit
sensor(config-sig-sig)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 11

Configuring Signature Fidelity Rating

Use the sig-fidelity-rating command in the signature definition submode to configure the signature
fidelity rating for a signature.
The following option applies:
To configure the signature fidelity rating for a signature, follow these steps:
Step 1
Log in to the CLI using an account with administrator or operator privileges.
Step 2
Enter signature definition submode:
sensor# configure terminal
sensor(config)# service signature-definition sig0
Choose the signature you want to configure:
Step 3
sensor(config-sig)# signatures 12000 0
Configure the fidelity rating for this signature:
Step 4
sensor(config-sig-sig)# sig-fidelity-rating 50
Step 5
Verify the settings:
sensor(config-sig-sig)# show settings
<protected entry>
sig-id: 12000
subsig-id: 0
-----------------------------------------------
78-16527-01
event-count-key: AxBx default: Axxx
specify-alert-interval
-----------------------------------------------
yes
-----------------------------------------------
alert-interval: 30 default: 60
-----------------------------------------------
-----------------------------------------------
sig-fidelity-rating—Identifies the weight associated with how well this signature might perform in
the absence of specific knowledge of the target.
The valid value is 0 to 100.
alert-severity: low <defaulted>
sig-fidelity-rating: 50 default: 85
promisc-delta: 15 <defaulted>
sig-description
-----------------------------------------------
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
Configuring Signatures
7-9

Advertisement

Table of Contents
loading

Table of Contents