CIDS signature types are as follows:
- General—Detect IP, ICMP, TCP,
and UDP intrusion attempts. CIDS signature series included are
1000, 2000, 3000, 4000, 5000, and 6000. The 3000 and 4000
connection request signatures are connection types. Some examples
of general signatures are IP fragments overlap, ICMP echo
requests, High Port Sweep, UDP bomb, DNS Zone Transfer Request,
WWW IIS Unicode Attack, and TFN Client request.
- Connection—Detect TCP
connection requests or traffic to UDP ports. CIDS signature ID is
either a 3000 or 4000 associated with a sub-signature ID
specifying the port. For instance, a connection request to TCP
port 21 would alarm with signature 3000 and sub-signature ID 21.
- String—Detect matches to
defined string patterns. CIDS signature series is 8000. For
example, you could define the string "hack". IP Traffic
with this string would trigger an alarm.
- ACL—Detect violations that
occur against defined Cisco IOS Access Control Lists (ACLs). CIDS
signature series is 10000.
|
|