6.8 8000 Series—String Match Signatures
6.8.1 String match signatures

There are two different signatures that belong in the 8000 series:

  • Custom string matches
  • TCP applications

The 8000 series—string match—signatures enable the network security administrator to create custom TCP signatures to detect specific string patterns. This flexibility provides the network security administrator the ability to implement and deploy on-the-fly signatures. Custom signatures commonly are used to do the following:

  • Act as a temporary signature for newly discovered vulnerabilities until an official CIDS signature is released.
  • Detect misuse based on offending keywords.
  • Protect specific network applications that CIDS does not have current signatures to detect possible attacks.

Custom signatures can be configured by specifying the following parameters:

  • TCP port number
  • Traffic direction (to or from port)
  • Number of occurrences
  • String

String signatures use a regular expression intrusion detection system engine. You may enter a UNIX-like regular expression as the string to match. The example string signature will match attempts to grab a UNIX shadow password file.