
B-24
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
78-16527-01
Appendix B Signature Engines
SERVICE Engines
SERVICE SMB Engine
The SERVICE.SMB engine inspects SMB packets. You can tune SMB signatures and create custom
SMB signatures based on SMB control transaction exchanges and SMB NT_Create_AndX exchanges.
Table B-21
lists the parameters specific to the SERVICE.SMB engine.
specify-port-map-program (Optional) Enables the portmapper program:
•
port-map-program—The program number sent
to the portmapper for this signature.
0 to 9999999999
specify-rpc-max-length
(Optional) Enables RPC maximum length:
•
rpc-max-length—Maximum allowed length of
the entire RPC message. Lengths longer than
what you specify fire an alert.
0 to 65535
specify-rpc-procedure
(Optional) Enables RPC procedure:
•
rpc-procedure—RPC procedure number for this
signature.
0 to 1000000
specify-rpc-program
(Optional) Enables RPC program:
•
rpc-program—RPC program number for this
signature.
0 to 1000000
1.
The second number in the range must be greater than or equal to the first number.
Table B-20
SERVICE.RPC Engine Parameters (continued)
Parameter
Description
Value
Table B-21
SERVICE.SMB Engine Parameters
Parameter
Description
Value
service-ports
A comma-separated list of ports or port ranges where
the target service resides.
0 to 65535
a-b[,c-d]
1
specify-allocation-hint
(Optional) Enables MS RPC allocation hint:
•
allocation-hint—MSRPC Allocation Hint, which is
used in SMB_COM_TRANSACTION command
parsing.
2
0 to 42949677295
specify-byte-count
(Optional) Enables byte count:
•
byte-count—Byte count from
SMB_COM_TRANSACTION structure.
3
0 to 65535
specify-command
(Optional) Enables SMB commands:
•
command—SMB command value.
4
0 to 255