Hi,
Can someone point to me to some good documentation on creating custom signatures for IDS 4235 sensor. The documentation CD is no good for creating custom signatures. Most of the fields in the signature wizard are not explained and I could not find explainations anywhere in the Cisco website.
For example, what are masks and how they are used with TCPFlags. What are StorageKeys (Axxx, AxBx, etc.) and how they are used. I do not see any documentation expalining these concepts.
Any help is highly appreciated.
Thank you,
Mo