Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual page 508

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Glossary
A component of the IPS. Performs packet capture and analysis. SensorApp analyzes network traffic for
SensorApp
malicious content. Packets flow through a pipeline of processors fed by a producer designed to collect
packets from the network interfaces on the sensor. Sensorapp is the standalone executable that runs
Analysis Engine.
Server Message Block. File-system protocol used in LAN manager and similar NOSs to package data
SMB
and exchange information with other systems.
Serial Number. Part of the UDI. The SN is the serial number of your Cisco product.
SN
Deals with specific protocols, such as DNS, FTP, H255, HTTP, IDENT, MS RPC, MS SL. NTP, RPC,
SERVICE engine
SMB, SNMP, and SSH.
Used for the release of bug fixes with no new enhancements. Service packs are cumulative following a
service pack
base version release (minor or major).
Command used on routers and switches to provide either Telnet or console access to a module in the
session command
router or switch.
Enables a dynamic response to an attacking host by preventing new connections and disallowing
shun command
packets from any existing connection. It is used by Network Access Controller when blocking with a
PIX Firewall.
See SAP.
Signature Analysis
Processor
A signature distills network information and compares it against a rule set that indicates typical
signature
intrusion activity.
A component of the sensor that supports many signatures in a certain category. An engine is composed
signature engine
of a parser and an inspector. Each engine has a set of legal parameters that have allowable ranges or
sets of values.
See SEAF.
signature event
action filter
See SEAH.
signature event
action handler
See SEAO.
signature event
action override
See SEAP.
signature event
action processor
Executable image that updates the IPS signature analysis engine (SensorApp) and the NSDB. Applying
signature update
an IPS signature update is like updating virus definitions on a virus scanning program. Signature
updates are released independently and have their own versioning scheme.
See SDP.
Slave Dispatch
Processor
Simple Mail Transfer Protocol. Internet protocol providing e-mail services.
SMTP
See sensing interface.
sniffing interface
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
GL-14
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents