B-7
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Appendix B Signature Engines
Master Engine
Obsoletes
The Cisco signature team uses the obsoletes field to indicate obsoleted, older signatures that have been
replaced by newer, better signatures, and to indicate disabled signatures in an engine when a better
instance of that engine is available. For example, some String XL hardware-accelerated signatures now
replace equivalent signatures that were defined in the String engine.
Vulnerable OS List
When you combine the vulnerable OS setting of a signature with passive OS fingerprinting, the IPS can
determine if it is likely that a given attack is relevant to the target system. If the attack is found to be
relevant, the risk rating value of the resulting alert receives a boost. If the relevancy is unknown, usually
because there is no entry in the passive OS fingerprinting list, then no change is made to the risk rating.
If there is a passive OS fingerprinting entry and it does not match the vulnerable OS setting of a
signature, the risk rating value is decreased. The default value by which to increase or decrease the risk
rating is +/- 10 points.
For More Information
For more information about promiscuous mode, see Understanding Promiscuous Mode, page 4 -14.
For more information about passive OS fingerprinting, see Configuring OS Identifications,
page 8-26.
Alert Frequency
The purpose of the alert frequency parameter is to reduce the volume of the alerts written to the Event
Store to counter IDS DoS tools, such as stick. There are four modes: fire-all, fire-once, summarize, and
global-summarize. The summary mode is changed dynamically to adapt to the current alert volume. For
example, you can configure the signature to fire-all, but after a certain threshold is reached, it starts
summarizing.
Tabl e B-2 lists the alert frequency parameters.
TableB-2 Master Engine Alert Frequency Parameters
Parameter Description Value
summary-mode Specifies the mode used for summarization:
fire-all—Fires an alert on all events.
fire-once—Fires an alert only once.
global-summarize—Summarizes an alert so
that it only fires once regardless of how
many attackers or victims.
summarize—Summarizes alerts.
fire-all
fire-once
global-summarize
summarize
specify-summary-threshold
{yes |no}
Enables summary threshold mode:
summary-threshold—Specifies the
threshold number of alerts to send a
signature into summary mode.
summary-interval—Specifies the time in
seconds used in each summary alert.
0 to 65535
1 to 1000