Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
IPS v5.08-1
Parameters Common to
All Signature Engines
IPS v5.08-2
Common Parameters
Signature ID
SubSignature ID
Alert Severity
Sig Fidelity
Rating
Sig
Description
Signature
Name
Alert Notes
Promiscuous Delta
Engine
Event Counter
Event Count
User
Comments
Alert
Traits
Release
Event
Count Key
Specify
Alert
Interval
2005 Cisco Systems, Inc. All rights reserved.
IPS v5.08-3
Alert
Frequency
Summary
Mode
Summary
Interval
Status
Enabled
Retired
2005 Cisco Systems, Inc. All rights reserved.
Summary
Key
Specify Global
Summary
Threshold
IPS v5.08-4
Summary Modes
You can use the value of the common
Parameter Summary mode to control the
number of alarms generated by a specific
signature. The Summary Mode parameter can
have one of the following values:
Fire once
Fire all
Summarize
Global summarize
IPS v5.08-5
Summary Mode
Summary Threshold
FireAll
Summarize
Summarize
2005 Cisco Systems, Inc. All rights reserved.
Global
Summarize
Global
Summarize
IPS v5.08-6
Signature Tuning
IPS v5.08-7
Signature Tuning
Configuration
Signature
Definition
Signature
Configuration
Edit
IPS v5.08-8
IPS v5.08-9
Alert Severity
Event
Action
IPS v5.08-10
You discover that Signature 4611 detects TFTP requests for DLink configuration files, but it does not meet your requirements to
do the following:
Generate a single alert for a single-source IP every 5 minutes
Drop the TFTP request before it reaches its target
2005 Cisco Systems, Inc. All rights reserved.
IPS v5.08-11
Configuration
Signature
Definition
Edit
Signature
Configuration
Select By:
Sig ID
IPS v5.08-12
Event
Counter
Event
Count
Key
Specify
Alert
Interval
Alert
Frequency
OK
2005 Cisco Systems, Inc. All rights reserved.
Summary
Mode
Alert
Interval
IPS v5.08-13
Custom Signatures
IPS v5.08-14
IPS v5.08-15
IPS v5.08-16
Signature
Definition
Custom
Signature
Wizard
Start the
Wizard
IPS v5.08-17
Select
Engine
Next
IPS v5.08-18
Signature
ID
Signature
Name
Next
IPS v5.08-19
Specify
Layer 4
Protocol
Layer 4
Protocol
TCP
Flags
TCP Mask
Next
IPS v5.08-20
Specify
Destination
Port Range
Destination
Port Range
Next
IPS v5.08-21
Signature
Fidelity
Rating
Severity of
the Alert
Next
IPS v5.08-22
Advanced
Finish
2005 Cisco Systems, Inc. All rights reserved.
IPS v5.08-23
IPS v5.08-24
IPS v5.08-25
No
Next
IPS v5.08-26
TCP
Next
IPS v5.08-27
Single TCP
Connection
Next
IPS v5.08-28
OTHER
Next
IPS v5.08-29
Signature ID
SubSignature ID
Signature Name
Alert Notes
User Comments
Next
IPS v5.08-30
Event Action
Regex String
Service Ports
Direction
Next
IPS v5.08-31
Signature
Fidelity Rating
Severity of
the Alert
Next
IPS v5.08-32
Advanced
IPS v5.08-33
Event Count
Event Count
Key
Use Event Interval
Event
Interval
Next
IPS v5.08-34
Alert Every
Time the
Signature
Fires
Next
IPS v5.08-35
Summary Key
Use Dynamic
Summarization
Specify
Global
Summary
Threshold
Summary
Threshold
Summary
Interval
(seconds)
Finish
Global
Summary
Threshold
IPS v5.08-36
Finish
2005 Cisco Systems, Inc. All rights reserved.
IPS v5.08-37
IPS v5.08-38
Signature
Definition
Select Engine
Select By
Add
Signature
Configuration
IPS v5.08-39
Alert
Severity
Sig Fidelity
Rating
Signature
Name
Engine
Event
Action
IPS v5.08-40
Component
List
IPS v5.08-41
Entry Key
Component
Sig ID
Add
Component
SubSig ID
OK
IPS v5.08-42
Available
Entries
Selected
Entries
Select
OK
IPS v5.08-43
Meta
Reset
Interval
Meta
Key
OK
IPS v5.08-44
Configuration
Select
By
Actions
Signature
Definition
Signature
Configuration
Produce
Alert
2005 Cisco Systems, Inc. All rights reserved.
IPS v5.08-45