<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fine tuning IDS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969717#M80277</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi attmidsteam &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a query regarding fine-tuning IDS Signatures . I am using old IDM (snapshots attached) .I wanto know if for a particular signature i want to disable the logging from specific source IP Range to destination IP Range , how to go about this in the same . Is it we do it via Event filter ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know how to do it in IDM 5 (we need to go to Event action filters and subtract the action ) .Kindly help me in &lt;/P&gt;&lt;P&gt;IDM 4 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ankur &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Apr 2008 06:57:56 GMT</pubDate>
    <dc:creator>ankurs2008</dc:creator>
    <dc:date>2008-04-17T06:57:56Z</dc:date>
    <item>
      <title>Fine tuning IDS</title>
      <link>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969715#M80275</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are going for tuning the IDS signature.No idea how to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please somebody suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanking u&lt;/P&gt;&lt;P&gt;Navin &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:04:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969715#M80275</guid>
      <dc:creator>navin_rk3</dc:creator>
      <dc:date>2019-03-10T11:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Fine tuning IDS</title>
      <link>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969716#M80276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your post leaves much information to be desired.  Do you want to tune a single signature or a group of signatures?  Do you want to simply disable a signature, or do you want to change the summarization key or regex patterns?  etc,etc,etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using the IDM, the sensor console CLI, or CSM?  Each method varies wildly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2008 16:59:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969716#M80276</guid>
      <dc:creator>attmidsteam</dc:creator>
      <dc:date>2008-04-16T16:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Fine tuning IDS</title>
      <link>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969717#M80277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi attmidsteam &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a query regarding fine-tuning IDS Signatures . I am using old IDM (snapshots attached) .I wanto know if for a particular signature i want to disable the logging from specific source IP Range to destination IP Range , how to go about this in the same . Is it we do it via Event filter ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know how to do it in IDM 5 (we need to go to Event action filters and subtract the action ) .Kindly help me in &lt;/P&gt;&lt;P&gt;IDM 4 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ankur &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Apr 2008 06:57:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969717#M80277</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2008-04-17T06:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Fine tuning IDS</title>
      <link>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969718#M80278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, if you want a filter a specific signature from a certain source range to a certain destination range, you'll use an event filter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Apr 2008 12:45:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969718#M80278</guid>
      <dc:creator>attmidsteam</dc:creator>
      <dc:date>2008-04-17T12:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Fine tuning IDS</title>
      <link>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969719#M80279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Attmidsteam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We got this new project recently,so we want fine tune or customize the signature as per our organisation traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Question is how to customize or how to use network tapps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are accessing the IDS through the IDM as well as CLI &amp;amp; we are not using CSM ,but monitored through the event viewer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanking u&lt;/P&gt;&lt;P&gt;Navin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Apr 2008 06:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969719#M80279</guid>
      <dc:creator>navin_rk3</dc:creator>
      <dc:date>2008-04-19T06:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Fine tuning IDS</title>
      <link>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969720#M80280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Configuring an Event Filter (as suggested by attmidsteam) is a very different question from how to use a network tap.&lt;/P&gt;&lt;P&gt;Do you have traffic to monitor arriving at your sensor? If not, then you need to either use a network tap (instrouction provided by the vendor) or use a switch with port spanning enabled for promiscious sniffing. For inline traffic, you need to create per-interface or VLAN pairs and cable your network traffic to flow through you IPS.&lt;/P&gt;&lt;P&gt;The CLI and IDM steps for configuring an Event Filter can be found here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a00808518b2.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a00808518b2.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Apr 2008 13:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969720#M80280</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2008-04-19T13:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Fine tuning IDS</title>
      <link>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969721#M80281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rhermes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Already the network setup is there .We want to Fine tune the IDS using Network tap &amp;amp; the vendor is Cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We don't know how to analyze the traffic? &amp;amp;  Ids is in promiscous mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank u&lt;/P&gt;&lt;P&gt;navin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Apr 2008 01:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969721#M80281</guid>
      <dc:creator>navin_rk3</dc:creator>
      <dc:date>2008-04-20T01:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Fine tuning IDS</title>
      <link>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969722#M80282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest hiring a professional or outsourcing the security at this point.  I can't explain how to be a competent security analyst in a paragraph.  You'll want someone with a lot of security experience who can first profile your network based upon the devices/servers in use, and then conduct detailed analysis of the events that are generated to determine which are valid and which are false positives.  This is typically a 24hr job as hackers/malware/botnets never sleep.  Good luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 19:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fine-tuning-ids/m-p/969722#M80282</guid>
      <dc:creator>attmidsteam</dc:creator>
      <dc:date>2008-04-22T19:59:51Z</dc:date>
    </item>
  </channel>
</rss>

