Overview
The Sensor devices monitor network traffic looking for attack signatures. This chapter explores the use of signatures in the CIDS environment. Each attack has particular characteristics that make it identifiable to the Sensor. Signatures can be content- or context-based and can be triggered by atomic or composite traffic. Each signature is part of a class and can be associated with a type. Signatures are further divided into series and severities. Each series is usually associated with a protocol.