6.1 Understanding Signatures
6.1.6 Signature severities
Severity levels are assigned to each CIDS signature. The severity of the signature represents the probability that the signature is an attack and the immediate threat to the network. The default severity levels are assigned by Cisco network security engineers. The signature severity level settings are configurable to allow for tuning to your network environment. There are three severity levels:
  • Severity 1: Low—These signatures detect network activity considered benign but for informational purposes. The following are examples of low severity signatures:
    • Unknown IP protocol
    • FTP SITE command attempted
  • Severity 3: Medium—These are signatures that detect abnormal network activity and could be perceived as malicious. Some of these signatures include legacy vulnerabilities that are not often seen on today's networks. The following are examples of medium severity signatures:
    • Net Sweep-echo
    • TCP SYN port sweep
  • Severity 5: High—These signatures detect attacks used to gain access or cause a denial of service (DoS). The following are examples of high severity signatures:
    • BackOrifice BO2K TCP Non Stealth 1
    • WWW IIS Unicode
    • sadmind buffer overflow

Note: CIDS has a severity 0, which signifies the alarm is disabled.

Interactive Syntax Activity  (Flash, 148 Kb)
  In this activity you will identify the signature series and categorize some common attacks.