Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Excluding or Including Specific Signatures

Nov 25,2008 by admin

image

Excluding or Including Specific Signatures

After viewing events for several days and analyzing the traffic along with the source and destination addresses, you may want to turn certain signatures off and others on. There could be several reasons why you would want to exclude signatures. They range from too many alarms to false positives being generated by legitimate traffic patterns such as networking monitoring tools using ICMP to check that a node is alive. The ICMP would trigger most ICMP alarms even though the traffic is perfectly legitimate. This tuning process of the sensor by excluding signatures that are not pertinent to your network, or perhaps turning some on that were previously off, will add quite a bit of value to your security effort.


133 times read

Related news

» Cisco IDS Alarms and Signatures
by admin posted on Nov 24,2008
» Configuring Signatures and Alarms
by admin posted on Nov 26,2008
» IDS MC and Signatures
by admin posted on Nov 26,2008
» Configuring IOS-Based IDS Signatures
by admin posted on Nov 26,2008
» Creating an Audit Rule
by alperen posted on Sep 15,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author