Cisco Systems IPS 7.1 Home Security System User Manual


  Open as PDF
of 1042
 
B-57
Cisco Intrusion Prevention System CLI Sensor Configuration Guide for IPS 7.1
OL-19892-01
Appendix B Signature Engines
Service Engines
specify-exact-match-offset
{yes | no}
(Optional) Enables exact match offset:
exact-match-offset—Specifies the exact
stream offset the Regex string must
report for a match to be valid.
0 to 65535
specify-min-match-length
{yes | no}
(Optional) Enables minimum match length:
min-match-length—Specifies the
minimum number of bytes the Regex
string must match.
0 to 65535
specify-regex-payload-sour
ce {yes | no}
(Optional) Enables payload source
inspection:
payload-source—Specifies the kind of
payload source inspection.
3
resource
smb-data
tcp-data
specify-scan-interval {yes |
no}
(Optional) Enables scan interval:
scan-interval—Specifies the interval in
seconds used to calculate alert rates.
1 to 131071
specify-tcp-flags {yes | no} (Optional) Enables TCP flags:
msrpc-tcp-flags—Specifies the MSRPC
TCP flags.
msrpc-tcp-flags-mask—Specifies the
MSRPC flags mask.
concurrent-execution
did-not-execute
first-fragment
last fragment
maybe-semantics
object-uuid
pending-cancel
reserved
specify-msrpc-over-smb-pd
u-type
(Optional) Enables MSRPC PDU type over
the SMB packet:
msrpc-over-smb-pdu-type—Specifies
the PDU type of MSRPC over the SMB
packet.
0 = Request
2 = Response
11 = Bind
12 = Bind Ack
specify-msrpc-over-smb-uui
d {yes | no}
(Optional) Enables MSRPC over UUID:
msrpc-over-smb-uuid—Specifies the
MSRPC UUID.
32-character string
composed of hexadecimal
characters 0-9, a-f, A-F.
swap-attacker-victim Swaps the attacker and victim addresses and
ports (source and destination) in the alert
message and in any actions taken.
true | false (default)
1. The second number in the range must be greater than or equal to the first number.
2. Currently supporting 37 (0x25) SMB_COM_TRANSACTION command \x26amp; 162 (0xA2)
SMB_COM_NT_CREATE_ANDX command.
3. TCP_Data performs Regex over entire packet, SMB_Data performs Regex on SMB payload only, Resource_DATA performs
Regex on SMB_Resource.
Table B-28 Service SMB Advanced Engine Parameters (continued)
Parameter Description Value