Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Signature and Alarm Management

Mar 10,2010 by alperen

image


Overview

In this chapter, you will learn how to:

  • Understand the CIDS signature series

  • Recognize signature structure and implementation

  • Make use of signature types

  • Know about signature classes

  • Understand signature series

  • Use signature categories

  • Learn about signature severities

  • View and manage alarms

  • Use Event Viewer customization

  • Configure preference settings

  • Understand the Network Security database

Sensors constantly monitor the network, looking for traffic that matches predefined signatures. Once a signature is matched, an alarm is generated, indicating the severity and signature that was matched. Signatures, which allow your sensors to detect intrusive activity, are a vital component of your IDS system. This chapter describes and details the CIDS signatures.

When the sensor matches a signature, an alarm is sent to the director platform. The director platform is then responsible for notifying security personnel. Each alarm has a severity associated with the matched signature. To insure the security of the network, you must be able to view these alarms using Event Viewer. During an actual attack on your network, sensors can generate a large number of alarms in a short period of time. If you’re unaware of the functionality of the Event Viewer, you can easily become overwhelmed with the number of alarms generated by your network sensors. To help with the understanding of the Event Viewer and the management of alarms, you should first understand the signatures that generate those alarm events.


895 times read

Related news

» Signature and Alarm Management Review
by alperen posted on Mar 20,2010
» Event Viewer
by alperen posted on Mar 17,2010
» CIDS Signatures
by alperen posted on Mar 10,2010
» Cisco IDS Alarms and Signatures
by admin posted on Nov 24,2008
» Configuring Signatures and Alarms
by admin posted on Nov 26,2008
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author