Creating Custom Signatures; Sequence For Creating A Custom Signature - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 7
Defining Signatures
Exit IP log submode:
Step 5
sensor(config-sig-ip)# exit
sensor(config-sig)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 6

Creating Custom Signatures

This section describes how to create custom signatures, and contains the following topics:

Sequence for Creating a Custom Signature

Use the following sequence when you create a custom signature:
Select a signature engine.
Step 1
Assign the signature identifiers:
Step 2
Step 3
Assign the engine-specific parameters.
The parameters differ for each signature engine, although there is a group of master parameters that
applies to each engine.
Step 4
Assign the alert response:
Assign the alert behavior.
Step 5
Apply the changes.
Step 6
78-16527-01
Sequence for Creating a Custom Signature, page 7-29
Example STRING.TCP Signature, page 7-30
Example SERVICE.HTTP Signature, page 7-32
Example MEG Signature, page 7-33
Signature ID
SubSignature ID
Signature name
Alert notes (optional)
User comments (optional)
Signature fidelity rating
Severity of the alert
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
Creating Custom Signatures
7-29

Advertisement

Table of Contents
loading

Table of Contents