<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Virus Update @ Cisco IPS, Version 6.1(1)E2 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/virus-update-cisco-ips-version-6-1-1-e2/m-p/1001534#M79381</link>
    <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   One of our customer has a ASA-SSM-10 IPS module on a ASA 5520. Yesterday I did an Signature Update and here is what I've found out:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Signature Definition:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Signature Update S435.0 2008-07-15&lt;/P&gt;&lt;P&gt; Virus Update V1.4 2007-03-02&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; As far as I know when you perform a signature update the virus parameters are updated as well. But the Virus Definitions date of March 2007!!! Pretty old.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I may be wrong though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; How can I update the Virus Definitions on the module? I searched the Download Software and couldn't find any update that mentioned specifically the Virus Definitions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Thanks in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Best Regards, Dan&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 11:12:20 GMT</pubDate>
    <dc:creator>daniel-costa</dc:creator>
    <dc:date>2019-03-10T11:12:20Z</dc:date>
    <item>
      <title>Virus Update @ Cisco IPS, Version 6.1(1)E2</title>
      <link>https://community.cisco.com/t5/network-security/virus-update-cisco-ips-version-6-1-1-e2/m-p/1001534#M79381</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   One of our customer has a ASA-SSM-10 IPS module on a ASA 5520. Yesterday I did an Signature Update and here is what I've found out:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Signature Definition:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Signature Update S435.0 2008-07-15&lt;/P&gt;&lt;P&gt; Virus Update V1.4 2007-03-02&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; As far as I know when you perform a signature update the virus parameters are updated as well. But the Virus Definitions date of March 2007!!! Pretty old.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I may be wrong though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; How can I update the Virus Definitions on the module? I searched the Download Software and couldn't find any update that mentioned specifically the Virus Definitions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Thanks in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Best Regards, Dan&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:12:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/virus-update-cisco-ips-version-6-1-1-e2/m-p/1001534#M79381</guid>
      <dc:creator>daniel-costa</dc:creator>
      <dc:date>2019-03-10T11:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Virus Update @ Cisco IPS, Version 6.1(1)E2</title>
      <link>https://community.cisco.com/t5/network-security/virus-update-cisco-ips-version-6-1-1-e2/m-p/1001535#M79386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dan, V 1.4 is the latest available.  The virus updates were being provided from Trend via a now defunct product, Incident Control Service (Server?).  The current V1.4 virus signatures are embodied in signatures in the 50001 ~ 50013 range, if I recall correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that signatures 50000-1 through -3 are also part of the ICS range, but used for throttling and should never be enabled outside of ICS control.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 18:10:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/virus-update-cisco-ips-version-6-1-1-e2/m-p/1001535#M79386</guid>
      <dc:creator>scothrel</dc:creator>
      <dc:date>2008-07-18T18:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Virus Update @ Cisco IPS, Version 6.1(1)E2</title>
      <link>https://community.cisco.com/t5/network-security/virus-update-cisco-ips-version-6-1-1-e2/m-p/1001536#M79388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott, I have a similar situation to Dan with an ASA-SSM-20. Do you know if we can expect regular Virus definitions to made available again in future IPS Signature updates?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brgds,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arthur.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Oct 2008 19:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/virus-update-cisco-ips-version-6-1-1-e2/m-p/1001536#M79388</guid>
      <dc:creator>aspring</dc:creator>
      <dc:date>2008-10-05T19:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Virus Update @ Cisco IPS, Version 6.1(1)E2</title>
      <link>https://community.cisco.com/t5/network-security/virus-update-cisco-ips-version-6-1-1-e2/m-p/1001537#M79390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This topic surfaces on a regular basis, so I'll quote two of the best answers from marcabal and mhellman.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Posted by: marcabal - Oct 18, 2007, 11:30am PST&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is the latest version. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The V signatures are created by Trend Micro Systems when a major virus/worm outbreak occurs and an emergency update is needed. &lt;/P&gt;&lt;P&gt;The V update could then be deployed through a Cisco ICS management server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, there has not been a major emergnecy outbreak in the past 2 years that has required a special V signature update. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead any signatures for virus/worms in the past 2 years have just been included as part of the standard signature update process and been included in our standard S signature levels without the need for special emergency updates. &lt;/P&gt;&lt;P&gt;Often the vulnerability was already detected by a standard S signature update before the virus/worm began spreading. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Posted by: mhellman - Jan 31, 2008, 12:44pm PST&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cbeb4ff" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cbeb4ff&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cbe28c5" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cbe28c5&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.1dde1bcf/0#selected_message" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.1dde1bcf/0#selected_message&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2008 15:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/virus-update-cisco-ips-version-6-1-1-e2/m-p/1001537#M79390</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2008-10-06T15:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Virus Update @ Cisco IPS, Version 6.1(1)E2</title>
      <link>https://community.cisco.com/t5/network-security/virus-update-cisco-ips-version-6-1-1-e2/m-p/1001538#M79392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for coming back so quickly. Your response has helped clear the issue for me. It would useful if Cisco provided this information in the Signature Readme files then perhaps the AV Update version would not be raised so often on the Forum&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brgds,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arthur.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2008 18:39:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/virus-update-cisco-ips-version-6-1-1-e2/m-p/1001538#M79392</guid>
      <dc:creator>aspring</dc:creator>
      <dc:date>2008-10-06T18:39:21Z</dc:date>
    </item>
  </channel>
</rss>

