Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Signature Series

Mar 10,2010 by alperen

image

CIDS organizes all the signatures into a series. When an alarm is sent, the signature that generated the alarm is also sent. The Event Viewer displays not only the alarm, but also the signature ID. While recognizing every signature ID that could generate an alarm would be difficult, you can tell from the series of the signature what type of signature was matched. Cisco has organized the signatures to allow for easier identification.

Each of the series is a collection of related signatures. The signature series are 1000, 2000, 3000, 4000, 5000, 6000, 8000, and 10000. The following is a list of all the signature series and the signatures found in each.


STUDY TIP 

Be aware of each signature series and the type of traffic monitored by each.

1000 Series Signatures—IP Signatures

Includes the following:

  • IP Options

  • IP fragmentation

  • Bad IP Packets

2000 Series Signatures—ICMP Signatures

Includes the following:

  • ICMP Traffic Records

  • Ping Sweeps

  • ICMP Attacks

3000 Series Signatures—TCP Signatures

Includes the following:

  • TCP Traffic Records

  • TCP Port Scans

  • TCP Host Sweeps

  • Mail Attacks

  • FTP Attacks

  • Legacy CIDS Web Attacks (Signature IDs 3200–3233)

  • NetBIOS Attacks

  • SYN Flood and TCP Hijack Attacks

  • TCP Applications

5000 Series Signatures—Web (HTTP) Signatures

Includes the following:

  • Web Attacks

6000 Series Signatures—Cross Protocol Signatures

Includes the following:

  • DNS Attacks

  • RPC Service Attacks

  • Authentication Failures

  • Loki Attacks

  • Distributed DoS Attacks

8000 Series Signatures—String Match Signatures

Includes the following:

  • Custom String Matches

  • TCP Applications

10000 Series Signatures—ACL Policy Violation Signatures

Includes the following:

  • Defined IOS ACL Violations


984 times read

Related news

» Signature and Alarm Management Review
by alperen posted on Mar 20,2010
» Understanding Cisco IDS Signature Series
by admin posted on Nov 25,2008
» Signature Types
by alperen posted on Mar 10,2010
» IDS MC and Signatures
by admin posted on Nov 26,2008
» Signature and Alarm Management
by alperen posted on Mar 10,2010
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author