10-41
Cisco Intrusion Detection System Appliance and Module Installation and Configuration Guide Version 4.1
78-15597-02
Chapter 10 Configuring the Sensor Using the CLI
Sensor Configuration Tasks
SERVICE.SMB SMB Service decode inspection.
SERVICE.SMTP SMTP Protocol Inspection Engine
SERVICE.SNMP Inspects SNMP traffic
SERVICE.SSH SSH header decode signatures.
SERVICE.SYSLOG Engine to process syslogs,
show Display system settings and/or history
information
ShunEvent Shun Event configuration tokens
STATE.STRING.CISCOLOGIN Telnet based Cisco Login Inspection
Engine
STATE.STRING.LPRFORMATSTRING LPR Protocol Inspection Engine
StreamReassembly Stream Reassembly configuration tokens
STRING.ICMP Generic ICMP based string search Engine
STRING.TCP Generic TCP based string search Engine.
STRING.UDP Generic UDP based string search Engine
SWEEP.HOST.ICMP ICMP host sweeps from a single attacker
to many victims.
SWEEP.HOST.TCP TCP-based Host Sweeps from a single
attacker to multiple victims.
SWEEP.MULTI UDP and TCP combined port sweeps.
SWEEP.OTHER.TCP Odd sweeps/scans such as nmap
fingerprint scans.
SWEEP.PORT.TCP Detects port sweeps between two nodes.
SWEEP.PORT.UDP Detects UDP connections to multiple
destination ports between two nodes.
systemVariables User modifiable system variables
TRAFFIC.ICMP Identifies ICMP traffic irregularities.
TROJAN.BO2K BackOrifice BO2K trojan traffic
TROJAN.TFN2K TFN2K trojan/ddos traffic
TROJAN.UDP Detects BO/BO2K UDP trojan traffic.
Step 6
Type the name of engine you want to see.
For example, to see the settings for the engine that inspects the Network Time
Protocol (NTP):
sensor(config-vsc-virtualSensor)# service.ntp
The prompt changes to indicate which signature engine you are in. In the example
above, the prompt would be:
sensor(config-vsc-virtualSensor-SER)#
.
Step 7
View the parameters for that specific signature engine:
sensor(config-vsc-virtualSensor-SER)# show settings
SERVICE.NTP
-----------------------------------------------
version: 4.0 <protected>
signatures (min: 0, max: 1000, current: 1)
-----------------------------------------------
Содержание IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor
Страница 4: ......
Страница 450: ...Appendix B Troubleshooting ...