Select the Custom Signatures tab, Add Custom
Signature, and Configure the settings in this table:
|
Custom Vulnerability and Spyware
Signature Settings
|
Description
|
|
Threat ID
|
Enter a numeric identifier for the configuration (spyware
signatures range is 15000-18000 and 6900001 - 7000000;
vulnerability signatures range is 41000-45000 and
6800001-6900000).
|
|
Name
|
Specify the threat name.
|
|
Comment
|
Enter an optional comment.
|
|
Severity
|
Assign a level that indicates the seriousness of the
threat.
|
|
Direction
|
Indicate whether the threat is assessed from the client to
server, server to client, or both.
|
|
Affected System
|
Indicate whether the threat involves the client, server,
either, or both. Applies to vulnerability signatures, but
not spyware signatures.
|
|
CVE
|
Specify the common vulnerability enumeration (CVE) as an
external reference for additional background and
analysis.
|
|
Vendor
|
Specify the vendor identifier for the vulnerability as an
external reference for additional background and
analysis.
|
|
Bugtraq
|
Specify the bugtraq (similar to CVE) as an external reference
for additional background and analysis.
|
|
Reference
|
Add any links to additional analysis or background
information. The information is shown when a user clicks on
the threat from the ACC, logs, or vulnerability profile.
|
|
Standard Signature
|
Select Standard and then
Add a new signature. Specify the
following information:
Standard—Enter a name to
identify the signature. Comment—Enter an optional
description. Ordered Condition Match—Select
if the order in which signature conditions are
defined is important. Scope—Select whether to apply
this signature only to the current transaction or to
the full user session.
Add a condition by clicking Add Or
Condition or Add And
Condition. To add a condition within a
group, select the group and then click Add
Condition. Add a condition to a signature so
that the signature is generated for traffic when the
parameters you define for the condition are true. Select an
Operator from the drop-down. The
operator defines the type of condition that must be true for
the custom signature to match to traffic. Choose from
Less Than, Equal
To, Greater Than, or
Pattern Match operators.
|
|
When choosing an Equal To,
Less Than, or
Greater Than operator,
specify for the following to be true for the
signature to match to traffic: Context—Select from
unknown requests and responses for TCP or UDP. Position—Select between
the first four or second four bytes in the
payload. Mask—Specify a 4-byte
hex value, for example, 0xffffff00. Value—Specify a 4-byte
hex value, for example, 0xaabbccdd.
|
|
Combination Signature
|
Select Combination and specify the
following information:
Select Combination Signatures to
specify conditions that define signatures:
Add a condition by clicking Add AND
Condition or Add OR
Condition. To add a condition within a
group, select the group and then click
Add Condition. To move a condition within a group, select the
condition and click Move Up
or Move Down. To move a
group, select the group and click Move
Up or Move
Down. You can't move conditions from one
group to another.
Select Time Attribute to specify the
following information:
Number of Hits—Specify the
threshold that will trigger any policy-based action
as a number of hits (1-1000) in a specified number
of seconds (1-3600). Aggregation Criteria—Specify
whether the hits are tracked by source IP address,
destination IP address, or a combination of source
and destination IP addresses. To move a condition within a group, select the
condition and click Move Up
or Move Down. To move a
group, select the group and click Move
Up or Move
Down. You can't move conditions from one
group to another.
|