B-36
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
AppendixB Signature Engines
Normalizer Engine
For More Information
For more information on the parameters common to all signature engines, see Master Engine,
page B-4.
For a list of the signature regular expression syntax, see Regular Expression Syntax, page B-9.
Normalizer Engine
Note
You cannot add custom signatures to the Normalizer engine. You can tune the existing ones.
regex-component Specifies the list of Regex components:
regex-string—Specifies the string to search
for.
spacing-type—Specifies the type of spacing
required from the match before or from the
beginning of the stream/packet if it is the first
entry in the list.
list (1 to 16 items)
exact
minimum
port-selection Specifies the type of TCP or UDP port to inspect:
both-ports—Specifies both source and
destination port.
dest-ports—Specifies a range of destination
ports.
source-ports—Specifies a range of source
ports.
1
0 to 65535
2
exact-spacing Specifies the exact number of bytes that must be
between this Regex string and the one before, or
from the beginning of the stream/packet if it is the
first entry in the list.
0 to 4294967296
min-spacing Specifies the minimum number of bytes that must
be between this Regex string and the one before, or
from the beginning of the stream/packet if it is the
first entry in the list.
0 to 4294967296
swap-attacker-victim Swaps the attacker and victim addresses and ports
(source and destination) in the alert message and in
any actions taken.
true | false (default)
1. Port matching is performed bidirectionally for both the client-to-server and server-to-client traffic flow directions. For
example, if the source-ports value is 80, in a client-to-server traffic flow direction, inspection occurs if the client port is 80.
In a server-to-client traffic flow direction, inspection occurs if the server port is port 80.
2. A valid value is a comma- separated list of integer ranges a-b[,c-d] within 0 to 65535. The second number in the range must
be greater than or equal to the first number.
TableB-16 Multi String Engine Parameters (continued)
Parameter Description Value