cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1252
Views
0
Helpful
2
Replies

IPS signatures vendor list

rick11
Level 1
Level 1

Hello community,

we are operating Cisco IPS sensors connected to FTD, however we noticed the category WEB-applications in the signature list it generates every month a lot of false positive alerts. I'm able to disable specific revision of signatures and in the following months might appear again under a new signature.

Would be possible to disable signatures for products that we don't have in use? For example: Oracle, Tomcat, Zoho, Wordpress  (Remove a vendor so it will not be download or updated in the future)
Looking forward for your feedback
Thank you!

2 Replies 2

To disable specific vendor signatures in Cisco IPS sensors, follow these steps:

1. Login to the Adaptive Security Device Manager (ASDM) and navigate to Configuration ) ASA FirePOWER Configuration ) Policies ) Intrusion Policy ) Intrusion Policy.
2. Click on the Edit option for the Intrusion Policy you want to modify.
3. In the Intrusion Policy Management page, scroll down to the Rules option in the navigational panel and click on it. This will take you to the Rule Management page.
4. To disable a specific vendor signature, you can use the Filter bar option to search for the signature by keyword. For example, if you want to disable signatures related to a specific vendor, you can use the vendor name as a keyword in the filter bar.
5. Once the signatures are filtered, select the ones you want to disable.
6. Choose the option "Rule State" and configure the state of the selected rules as "Disable". This will disable the selected vendor signatures.
7. Click on OK to save the changes.

By following these steps, you can disable specific vendor signatures in Cisco IPS sensors.

Now, about the false positives from the category WEB-applications, they can be handled as follows:

1. If the alert is truly a false positive, you can customize your IPS sensor to ignore these alerts going forward.
2. Additionally, you can make use of Cisco's risk rating system to prioritize alerts and adjust the risk rating threshold for alert generation.
3. Lastly, Cisco provides alert verification features through which you can confirm whether the alert is a false positive or not.

Feel free to follow up if you have further questions or need more clarity on this.

This response was generated by a Cisco-powered AI bot and vetted by a Cisco Support Engineer prior to publication.
This is part of a monitored experiment to see if the bot can help answer questions alongside community members. You can help by giving the response a Helpful vote, accepting it as a Solution or leaving a reply if the response is incomplete or inaccurate.

Thank you, can you provide more details regarding point 2 and 3 ?

Review Cisco Networking for a $25 gift card