Service.snmp Engine - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

SERVICE Engines
Table B-21
Parameter
specify-word-count
swap-attacker-victim
1. The second number in the range must be greater than or equal to the first number.
2. An exact match is optional.
3.
4. An exact match is required. Currently supporting the 37 (0x25) SMB_COM_TRANSACTION command \x26amp and the
5. An exact match is optional.
6.
7. Valid for signatures 3302 and 6255 only.
8. Valid for signatures 3302 and 6255 only.
9. An exact match is required. Usually two are required for SMB_COM_TRANSACTION commands.
10. An exact match is required. Only 16 word transactions are decoded.

SERVICE.SNMP Engine

The SERVICE.SNMP engine inspects all SNMP packets destined for port 161. You can tune SNMP
signatures and create custom SNMP signatures based on specific community names and object
identifiers.
Instead of using string comparison or regular expression operations to match the community name and
object identifier, all comparisons are made using the integers to speed up the protocol decode and reduce
storage requirements.
Table B-22
Table B-22
Parameter
inspection-type
brute-force-inspection
invalid-packet-inspection
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
B-26
SERVICE.SMB Engine Parameters (continued)
Description
(Optional) Enables word counting for command
parameters:
word-count—Word count for the
SMB_COM_TRANSACTION command
parameters.
True if address (and ports) source and destination are
swapped in the alert message. False for no swap
(default).
An exact match is optional.
162 (0xA2) SMB_COM_NT_CREATE_ANDX command.
An exact match is required. Required for SMB_COM_TRANSACTION commands.
lists the parameters specific to the SERVICE.SNMP engine.
SERVICE.SNMP Engine Parameters
10
Description
Type of inspection to perform.
Inspects for brute force attempts:
brute-force-count—The number of unique
SNMP community names that constitute a
brute force attempt.
Inspects for SNMP protocol violations.
Appendix B
Signature Engines
Value
0 to 255
true | false
Value
0 to 65535
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents