|
The Sensor devices monitor network
traffic looking for attack signatures. This chapter explores the use
of signatures in the CIDS environment. Each attack has particular
characteristics that make it identifiable to the Sensor. Signatures
can be content- or context-based and can be triggered by atomic or
composite traffic. Each signature is part of a class and can be
associated with a type. Signatures are further divided into series and
severities. Each series is usually associated with a protocol.
|
|