Summary
Now that you have completed this chapter, you should have a firm understanding of the following:
  • Each signature can generate a unique alarm and response.
  • Context signatures are triggered by information in the packet header.
  • Content signatures are triggered by information in the packet payload.
  • Atomic signatures are triggered by information in a single packet.
  • Composite signatures are triggered by information in multiple packets.
  • Reconnaissance signatures are triggered by attempts to discover systems, services, or vulnerabilities.
  • Access signatures are triggered by unauthorized attempts to retrieve data, access systems, or escalate privileges.
  • DoS signatures are triggered by attempts to disable networks, systems, or services.
  • Information signatures collect information to help determine the validity of an attack, or for forensics.
  • Signature series generally group protocol related signatures under a single category.
  • The default signature severities are:
    • Low (1) indicates informational activity
    • Medium (3) indicates marginal attack activity
    • High (5) indicates severe attack activity