6.1 Understanding Signatures
6.1.4 Signature types
CIDS signature types are as follows:
  • General—Detect IP, ICMP, TCP, and UDP intrusion attempts. CIDS signature series included are 1000, 2000, 3000, 4000, 5000, and 6000. The 3000 and 4000 connection request signatures are connection types. Some examples of general signatures are IP fragments overlap, ICMP echo requests, High Port Sweep, UDP bomb, DNS Zone Transfer Request, WWW IIS Unicode Attack, and TFN Client request.
  • Connection—Detect TCP connection requests or traffic to UDP ports. CIDS signature ID is either a 3000 or 4000 associated with a sub-signature ID specifying the port. For instance, a connection request to TCP port 21 would alarm with signature 3000 and sub-signature ID 21.
  • String—Detect matches to defined string patterns. CIDS signature series is 8000. For example, you could define the string "hack". IP Traffic with this string would trigger an alarm.
  • ACL—Detect violations that occur against defined Cisco IOS Access Control Lists (ACLs). CIDS signature series is 10000.