Atomic.ip Engine - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix B
Signature Engines
Table B-5
Parameter
specify-mac-flip
specify-type-of-arp-sig
specify-request-inbalance
specify-arp-operation

ATOMIC.IP Engine

The ATOMIC.IP engine defines signatures that inspect IP protocol headers and associated Layer-4
transport protocols (TCP, UDP, and ICMP) and payloads.
The ATOMIC engines do not store persistent data across packets. Instead they can fire an alert from the
Note
analysis of a single packet.
Table B-6
Table B-6
Parameter
fragment-status
specify-ip-payload-length
specify-ip-header-length
specify-ip-addr-options
specify-ip-id
specify-ip-total-length
specify-ip-option-inspection
specify-l4-protocol
specify-ip-tos
specify-ip-ttl
specify-ip-version
78-16527-01
ATOMIC.ARP Engine Parameters
Description
Fires an alert when the MAC address changes more than this many
times for this IP address.
Specifies the type of ARP signatures you want to fire on:
Source Broadcast (default)—Fires an alarm for this signature when
it sees an ARP source address of 255.255.255.255.
Destination Broadcast—Fires an alarm for this signature when it
sees an ARP destination address of 255.255.255.255.
Same Source and Destination—Fires an alarm for this signature
when it sees an ARP destination address with the same source and
destination MAC address
Source Multicast—Fires an alarm for this signature when it sees an
ARP source MAC address of 01:00:5e:(00-7f).
Fires an alert when there are this many more requests than replies on
the IP address.
The ARP operation code for this signature.
lists the parameters that are specific to the ATOMIC.IP engine.
ATOMIC.IP Engine Parameters
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
Description
Specifies whether or not fragments are wanted.
Specifies IP datagram payload length.
Specifies IP datagram header length.
Specifies IP addresses.
Specifies IP identifier.
Specifies IP datagram total length.
Specifies IP options inspection.
Specifies Layer-4 protocol.
Specifies type of server.
Specifies time to live.
Specifies IP protocol version.
ATOMIC Engine
B-9

Advertisement

Table of Contents
loading

Table of Contents