10-04-2004 05:11 AM - edited 03-09-2019 08:58 AM
Where I will find very basics of Cisco IDS, its working and features?
I want the details on signatures, adding/making changes in signatures, threat response etc
10-04-2004 09:10 AM
10-04-2004 10:09 AM
Thanks for that.
I need online material...
10-04-2004 11:31 AM
A good starting place is:
http://www.cisco.com/en/US/products/hw/vpndevc/index.html#products
Look for the Network Intrusion Detection section to see the different product sections.
FYI: Many of these IDS product sections are just different representations of the same information and many contain links to the same underlying documents.
What I generally point users to is the Universal Documentation CD if they ask about User guides. All of the documentation on the CD is also available online. These same docs are in the product sections from above, but are organized in a simpler manner by product version on the CD.
Link to the online doc CD for the IDS documentation:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/index.htm
For the few specific questions you asked:
details on signatures, adding/making changes in signatures:
The first place to look is the NSDB. It is available on the sensor itself through a link in the top right corner of IDM. It provides information about each signature.
The same information is also available on Cisco's web site:
http://www.cisco.com/cgi-bin/front.x/csec/idsHome.pl
To see what parameters make up the actual signature I recommend viewing them through IDM:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids10/idmiev/swchap3.htm#wp31460
Once you see what parameters make up the signature you can find out more about what each parameter means in the IDM documentation:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids10/idmiev/swappa.htm
For threat response:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/threat/ctr20/index.htm
10-04-2004 04:44 PM
Some good online start points:
http://www.sans.org/rr/catindex.php?cat_id=30
http://www.cisco.com/pcgi-bin/Support/browse/index.pl?i=Products&f=5891
sincerely
Patrick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide