
7-29
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
78-16527-01
Chapter 7 Defining Signatures
Creating Custom Signatures
Step 5
Exit IP log submode:
sensor(config-sig-ip)#
exit
sensor(config-sig)#
exit
Apply Changes:?[yes]:
Step 6
Press
Enter
to apply the changes or type
no
to discard them.
Creating Custom Signatures
This section describes how to create custom signatures, and contains the following topics:
•
Sequence for Creating a Custom Signature, page 7-29
•
Example STRING.TCP Signature, page 7-30
•
Example SERVICE.HTTP Signature, page 7-32
•
Example MEG Signature, page 7-33
Sequence for Creating a Custom Signature
Use the following sequence when you create a custom signature:
Step 1
Select a signature engine.
Step 2
Assign the signature identifiers:
•
Signature ID
•
SubSignature ID
•
Signature name
•
Alert notes (optional)
•
User comments (optional)
Step 3
Assign the engine-specific parameters.
The parameters differ for each signature engine, although there is a group of master parameters that
applies to each engine.
Step 4
Assign the alert response:
•
Signature fidelity rating
•
Severity of the alert
Step 5
Assign the alert behavior.
Step 6
Apply the changes.