cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
581
Views
0
Helpful
2
Replies

New signature for flood control

gm-douglas
Level 1
Level 1

I am in need of help in writing my own signature to control dictionary attacks on a proprietary application on one of our main frame applications.

I was looking at writing a rule using the flood net engine. Does anyone have more information on what the different variables for this engine are? If I set the rate for 3 and the peaks and gaps to 0, will this block the 4th attempt in a second?

I also need to try to lock this signature down. I could not allow it to block every 4th connection attempt from one IP address. How can you lock this signature down to a specific port and IP address? Does it need to be written into a meta engine signature?

Thanks

Gary

1 Accepted Solution

Accepted Solutions

mhellman
Level 7
Level 7

details matter, but that seems like a less than optimal choice for the engine. Load up the signature policy and do a select by "sig name". Enter "failure" in the sig name box and click find. You might try modeling a signature after the one of these (6256-0 for example). Is there anything in the response that you can look for?

View solution in original post

2 Replies 2

mhellman
Level 7
Level 7

details matter, but that seems like a less than optimal choice for the engine. Load up the signature policy and do a select by "sig name". Enter "failure" in the sig name box and click find. You might try modeling a signature after the one of these (6256-0 for example). Is there anything in the response that you can look for?

Thank you. You got me going in the right direction. I created the rule with the Atomic IP engine, and it is working fine.

Gary

Review Cisco Networking for a $25 gift card