A-11
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Appendix A Intrusion Detection System Architecture
System Components
SensorApp
SensorApp, the sensing engine, is made up of two major components, the
VirtualSensor and the VirtualAlarm, which in turn are made up of nine major
functional units:
Note
Although VirtualSensor allows you to run multiple virtual sensors on the same
appliance and to configure each with different signature behavior and traffic
feeds, at this time IDS 4.x only supports one virtual sensor.
Note
The legacy application is packetd.
•
Kernel memory management module (KMMM)—Maintains ring and data
integrity by mediating access to the ring buffer.
•
Packet capture module (PCM)—Captures packets and places them in a
kernel/user shared memory ring buffer for further processing.
•
L2/L3/L4 parser (L2/L3/L4P)—Parses the L2/3/4 packet information and
puts the required information into the IDS header. If needed, the IDS header
of the packet is marked for reassembly by the fragment reassembly unit.
•
Fragment reassembly unit (FRU)—Processes packets that are marked for it.
The FRU has a separate ring buffer for the reassembly process.
•
TCP stream reassembly unit (SRU)—Determines if a packet belongs to a
known stream or if it is the first packet in a new stream. The SRU follows
predefined stream reassembly constraints to determine if the packet should be
queued for processing downstream or dropped.
•
Regular expression string search engine (RSSE)—Used for analysis of stream
and packet payloads for the existence of certain patterns that when combined
with other data may indicate the presence of an attack underway.
•
Signature micro-engines (SME)—Supports many signatures in a certain
category. An engine is composed of a parser and an inspector. Each engine
has a set of legal parameters that have allowable ranges or sets of values.
Summary of Contents for IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Page 4: ......
Page 450: ...Appendix B Troubleshooting ...