B-13
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
78-16527-01
Appendix B Signature Engines
SERVICE Engines
SERVICE Engines
The SERVICE engines analyze L5+ traffic between two hosts. These are one-to-one signatures that track
persistent data. The engines analyze the L5+ payload in a manner similar to the live service.
The SERVICE engines have common characteristics but each engine has specific knowledge of the
service that it is inspecting. The SERVICE engines supplement the capabilities of the generic string
engine specializing in algorithms where using the string engine is inadequate or undesirable.
This section contains the following topics:
•
SERVICE.DNS Engine, page B-14
•
SERVICE.FTP Engine, page B-15
•
SERVICE.GENERIC Engine, page B-16
•
SERVICE.H225 Engine, page B-16
•
SERVICE.HTTP Engine, page B-19
•
SERVICE.IDENT Engine, page B-20
•
SERVICE.MSRPC Engine, page B-21
•
SERVICE.MSSQL Engine, page B-22
•
SERVICE.NTP Engine, page B-22
•
SERVICE.RPC Engine, page B-23
specify-max-fragments-per-dgram (Optional) Enables maximum fragments per datagram.
specify-max-last-fragments
(Optional) Enables maximum last fragments.
specify-max-partial-dgrams
(Optional) Enables maximum partial datagrams.
specify-max-small-frags
(Optional) Enables maximum small fragments.
specify-min-fragment-size (Optional) Enables minimum fragment size.
specify-service-ports (Optional) Enables service ports.
specify-syn-flood-max-embrionic
(Optional) Enables SYN flood maximum embryonic.
specify-tcp-closed-timeout
(Optional) Enables TCP closed timeout.
specify-tcp-embryonic-timeout
(Optional) Enables TCP embryonic timeout.
specify-tcp-idle-timeout
(Optional) Enables TCP idle timeout.
specify-tcp-max-mss
(Optional) Enables TCP maximum mss.
specify-tcp-max-queue
(Optional) Enables TCP maximum queue.
specify-tcp-min-mss
(Optional) Enables TCP minimum mss.
specify-tcp-option-number
(Optional) Enables TCP option number.
Table B-10
NORMALIZER Engine Parameters (continued)
Parameter
Description