RE: Creating Signatures on Cisco IDS enabled IOS based Firewalls

From: McGill, Lachlan (mcgilll1_at_anz.com)
Date: 09/26/03

  • Next message: Steve Marin: "RE: PIX firewall and ICMP"
    Date: Fri, 26 Sep 2003 09:10:35 +1000
    To: "Cherian M. Palayoor" <cpalayoor@cwalkergroup.com>, <security-basics@securityfocus.com>
    
    

    No, you cannot create your own signatures for IOS based IDS. Signatures are upgraded by upgrading the IOS.

    -----Original Message-----
    From: Cherian M. Palayoor [mailto:cpalayoor@cwalkergroup.com]
    Sent: Friday, 26 September 2003 6:25 AM
    To: security-basics@securityfocus.com
    Subject: Creating Signatures on Cisco IDS enabled IOS based Firewalls

    Hi,

    Can anyone tell me if it is possible to create signatures using the IDS on a
    Cisco IOS based firewall.

    If yes, can you direct me to the documenetation on the same.

    Regards

    CP

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Steve Marin: "RE: PIX firewall and ICMP"

    Relevant Pages

    • Re: Value of "richer" signatures?
      ... Snort, Dragon, and NFR, and I can tell you that they ... Here's an example of how the newer IDS signatures help ... Let's say you are using a simple packet grepping IDS ... > an FTP connection). ...
      (Focus-IDS)
    • RE: Value of "richer" signatures?
      ... Is it that much faster to do "protocol parsing" than ... > Here's an example of how the newer IDS signatures help ... > Let's say you are using a simple packet grepping IDS ...
      (Focus-IDS)
    • Re: Advice on IDS product - Pt 2
      ... Just posted a question about IDS products and got several ... > Cisco IOS to the FW/IDS version as the two most likely ways to go. ... > the firewall features will give me a 30% performance loss. ...
      (comp.security.firewalls)
    • RE: Testing IDS/IPS Signatures
      ... can a scanner be used to validate the IDS ... True, Nessus can help in testing signatures but IMHO, it has limitations. ... > service features in Nessus and NeWT to see what is in fact ...
      (Focus-IDS)
    • RE: Comparing the performance of two IDS products with different architectures
      ... Comparing the performance of two IDS products with different architectures ... An interesting point, “a packet is only tested for a signature when needed, and not when it isn't ... and only tests signatures that apply to those contents. ... could argue all day long about the strengths and weaknesses of “pattern matching” vs “protocol ...
      (Focus-IDS)