We are seeing events triggered by this signature that appear to be invalid. SSH2 connection attempts appear to be triggering these events, when the exploit is clearly for SSH1. The signature is utilizing the SSH1 engine, but ssh1 is disabled on the...