Now that you have completed this chapter,
you should have a firm understanding of the following:
- Each signature can generate a unique
alarm and response.
- Context signatures are triggered by information in the packet header.
- Content signatures are triggered by
information in the packet payload.
- Atomic signatures are triggered by
information in a single packet.
- Composite signatures are triggered
by information in multiple packets.
- Reconnaissance signatures are
triggered by attempts to discover systems, services, or
vulnerabilities.
- Access signatures are triggered by
unauthorized attempts to retrieve data, access systems, or
escalate privileges.
- DoS signatures are triggered by
attempts to disable networks, systems, or services.
- Information signatures collect
information to help determine the validity of an attack, or for
forensics.
- Signature series generally group
protocol related signatures under a single category.
- The default signature severities
are:
- Low (1) indicates informational
activity
- Medium (3) indicates marginal
attack activity
- High (5) indicates severe attack
activity
|
|