Severity levels are assigned to each CIDS
signature. The severity of the signature represents the probability
that the signature is an attack and the immediate threat to the
network. The default severity levels are assigned by Cisco network
security engineers. The signature severity level settings are
configurable to allow for tuning to your network environment. There
are three severity levels:
- Severity 1: Low—These signatures
detect network activity considered benign but for informational
purposes. The following are examples of low severity signatures:
- Unknown IP protocol
- FTP SITE command attempted
- Severity 3: Medium—These are
signatures that detect abnormal network activity and could be
perceived as malicious. Some of these signatures include legacy
vulnerabilities that are not often seen on today's networks. The
following are examples of medium severity signatures:
- Net Sweep-echo
- TCP SYN port sweep
- Severity 5: High—These signatures
detect attacks used to gain access or cause a denial of service (DoS).
The following are examples of high severity signatures:
- BackOrifice BO2K TCP Non Stealth
1
- WWW IIS Unicode
- sadmind buffer overflow
Note: CIDS has a severity 0,
which signifies the alarm is disabled.
 |
 |
Interactive
Syntax Activity (Flash,
148 Kb) |
| |
In this
activity you will identify the signature series and categorize some common attacks. |
|
|
|
|