B-62
Cisco Intrusion Prevention System CLI Sensor Configuration Guide for IPS 7.1
OL-19892-01
Appendix B Signature Engines
State Engine
Table B-32 lists the parameters specific to the State engine.
Table B-32 State Engine Parameters
Parameter Description Value
state-machine Specifies the state machine grouping. cisco-login
lpr-format-string
smpt
cisco-login Specifies the state machine for Cisco login:
• state-name—Name of the state required before the
signature fires an alert:
–
Cisco device state
–
Control-C state
–
Password prompt state
–
Start state
cisco-device
control-c
pass-prompt
start
lpr-format-string Specifies the state machine to inspect for the LPR
format string vulnerability:
• state-name—Name of the state required before the
signature fires an alert:
–
Abort state to end LPR Format String
inspection
–
Format character state
–
State state
abort
format-char
start
smpt Specifies the state machine for the SMTP protocol:
• state-name—Name of the state required before the
signature fires an alert:
–
Abort state to end LPR Format String
inspection
–
Mail body state
–
Mail header state
–
SMTP commands state
–
Start state
abort
mail-body
mail-header
smtp-commands
start
specify-min-match-
length {yes | no}
(Optional) Enables minimum match length:
• min-match-length—Specifies the minimum
number of bytes the regular expression string must
match.
0 to 65535
regex-string Specifies the regular expression to search for.
Note This parameter is protected; you cannot edit it.
string