Professional Documents
Culture Documents
IPS50SL08
IPS50SL08
Configuring Signatures
SubSignature ID
Alert Severity
Sig Signature
Description Name
Sig Fidelity
Rating
Alert Notes
Promiscuous Delta
User
Comments
Engine
Alert
Event Counter Traits
Event Count
Release
Event
Count Key
Specify
Alert
Interval
© 2005 Cisco Systems, Inc. All rights reserved. IPS v5.0—8-3
Common Parameters (Cont.)
Alert
Frequency
Summary
Mode
Summary
Interval
Summary
Key
Status
• A = source address
• a = source port
• B = destination address
• b = destination port
• x = does not matter
Summary Interval
Global
FireAll Summarize
Summarize
Summarize Global
Summarize
© 2005 Cisco Systems, Inc. All rights reserved. IPS v5.0—8-7
Signature Tuning
Configuration
Signature
Definition
Signature
Configuration
Edit
Alert Severity
Event
Action
Enter Sig
ID: 4611
Configuration Find
Signature
Definition
Edit
Select By:
Signature Sig ID
Configuration
Event
Action
Event
Event
Counter
Count
Key
Specify
Alert
Alert Interval
Frequency
Summary Alert
Mode Interval
OK
Configuration
Signature
Definition
Custom
Signature
Wizard
Start the
Wizard
Select
Engine
Next
Signature
ID
Signature
Name
Next
Specify
Layer 4
Protocol
Layer 4
Protocol
TCP
Flags
TCP
Mask
Next
Specify
Destination
Port Range
Destination
Port Range
Next
Signature
Fidelity
Rating
Severity of
the Alert
Next
Advanced
Finish
© 2005 Cisco Systems, Inc. All rights reserved. IPS v5.0—8-24
Custom Signature Scenario 2
No
Next
TCP
Next
Single TCP
Connection
Next
OTHER
Next
Signature ID
Alert Notes
User Comments
Next
Event Action
Regex String
Service Ports
Direction
Next
Signature
Fidelity Rating
Severity of
the Alert
Next
Advanced
Event Count
Event Count
Key
Use Event Interval
Event
Interval
Next
Alert Every
Time the
Signature
Fires
Next
Summary Key
Summary
Specify Interval
Global (seconds)
Summary
Threshold
Finish
Global
Summary
Threshold
Finish
© 2005 Cisco Systems, Inc. All rights reserved. IPS v5.0—8-38
Custom Signature Scenario 3
Configuration
Select Engine
Signature Select By
Definition
Add
Signature
Configuration
Signature
ID
Alert
SubSignature Severity
ID
Sig Fidelity
Sig Rating
Description
Signature
Name
Engine
Event
Action
Component
List
Entry Key
Component
Add Sig ID
Component
SubSig ID
OK
Available
Entries
Selected
Entries
Select
OK
Meta
Reset
Interval
Meta
Key
OK
Enter
Sig ID
Configuration
Select
By
Actions
Signature
Definition
Signature
Configuration
Produce
Alert
© 2005 Cisco Systems, Inc. All rights reserved. IPS v5.0—8-46
Summary
Web
FTP
.50
172.26.26.0
.150
172.30.P.0 .1 .1 172.30.Q.0
.2 .2
RBB
prP prQ
172.16.Q.0
172.16.P.0 .1 .1
.4 .4
sensorP sensorQ
.2 .2
rP rQ
10.0.P.0 .2 .2 10.0.Q.0
.100
.100
RTS
RTS
Student PC Student PC
10.0.Q.12 10.0.Q.12
© 2005 Cisco Systems, Inc. All rights reserved. IPS v5.0—8-51