<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Creating custom signatures in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/creating-custom-signatures/m-p/492653#M99188</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone point to me to some good documentation on creating custom signatures for IDS 4235 sensor. The documentation CD is no good for creating custom signatures. Most of the fields in the signature wizard are not explained and I could not find explainations anywhere in the Cisco website.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, what are masks and how they are used with TCPFlags. What are StorageKeys (Axxx, AxBx, etc.) and how they are used. I do not see any documentation expalining these concepts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is highly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Mo&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:30:28 GMT</pubDate>
    <dc:creator>m.mohanasundaram</dc:creator>
    <dc:date>2019-03-10T09:30:28Z</dc:date>
    <item>
      <title>Creating custom signatures</title>
      <link>https://community.cisco.com/t5/network-security/creating-custom-signatures/m-p/492653#M99188</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone point to me to some good documentation on creating custom signatures for IDS 4235 sensor. The documentation CD is no good for creating custom signatures. Most of the fields in the signature wizard are not explained and I could not find explainations anywhere in the Cisco website.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, what are masks and how they are used with TCPFlags. What are StorageKeys (Axxx, AxBx, etc.) and how they are used. I do not see any documentation expalining these concepts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is highly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Mo&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:30:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-custom-signatures/m-p/492653#M99188</guid>
      <dc:creator>m.mohanasundaram</dc:creator>
      <dc:date>2019-03-10T09:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Creating custom signatures</title>
      <link>https://community.cisco.com/t5/network-security/creating-custom-signatures/m-p/492654#M99189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The following is a general parameter of the MASTER engine which applies to all signatures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Parameter - event-count-key&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Description - The storage type on which to count events for this signature:&lt;/P&gt;&lt;P&gt;&amp;#21;Attacker address&lt;/P&gt;&lt;P&gt;&amp;#21;Attacker and victim addresses&lt;/P&gt;&lt;P&gt;&amp;#21;Attacker address and victim port&lt;/P&gt;&lt;P&gt;&amp;#21;Victim address&lt;/P&gt;&lt;P&gt;&amp;#21;Attacker and victim addresses and ports&lt;/P&gt;&lt;P&gt;	&lt;/P&gt;&lt;P&gt;Value - &lt;/P&gt;&lt;P&gt;Axxx&lt;/P&gt;&lt;P&gt;AxBx&lt;/P&gt;&lt;P&gt;Axxb&lt;/P&gt;&lt;P&gt;xxBx&lt;/P&gt;&lt;P&gt;AaBb &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/cliguide/clisgeng.htm#wp1007746" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/cliguide/clisgeng.htm#wp1007746&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2005 14:56:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-custom-signatures/m-p/492654#M99189</guid>
      <dc:creator>owillins</dc:creator>
      <dc:date>2005-06-28T14:56:19Z</dc:date>
    </item>
  </channel>
</rss>

