08-24-2011 12:25 PM - edited 03-10-2019 05:27 AM
Hello,
How does the IPS Signature Development Team determine when a signature is obsolete? Is there ever a reason to un-retire a signature which has been set as Retired through the application of a signature update package?
Solved! Go to Solution.
08-24-2011 09:52 PM
Mark,
Usually an Obsolete signature is the result of a new sig that just came up. Lets say that there is signature 1 that looks for event A. Then the BU comes with signature 2 which looks for event A or event B (usually a variant of event A ) or with signature #3 that has a more eficient way to look for event A. So they decide to Obsolete Signature #1.
Also, there is no real reason to un-retire a retired signature. Retired signatures are usually signatures that fire a lot of false positives and generate a lot of noise.
Here is what the documentation says about this:
Obsoletes
The Cisco signature team uses the obsoletes field to indicate obsoleted, older signatures that have been replaced by newer, better signatures, and to indicate disabled signatures in an engine when a better instance of that engine is available.
I hope that this answers your questions.
Have fun
Raga
08-24-2011 09:52 PM
Mark,
Usually an Obsolete signature is the result of a new sig that just came up. Lets say that there is signature 1 that looks for event A. Then the BU comes with signature 2 which looks for event A or event B (usually a variant of event A ) or with signature #3 that has a more eficient way to look for event A. So they decide to Obsolete Signature #1.
Also, there is no real reason to un-retire a retired signature. Retired signatures are usually signatures that fire a lot of false positives and generate a lot of noise.
Here is what the documentation says about this:
Obsoletes
The Cisco signature team uses the obsoletes field to indicate obsoleted, older signatures that have been replaced by newer, better signatures, and to indicate disabled signatures in an engine when a better instance of that engine is available.
I hope that this answers your questions.
Have fun
Raga
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide