Glossary
GL-12
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
L
LACP
Link Aggregation Control Protocol. LACP aids in the automatic creation of EtherChannel links by
exchanging LACP packets between LAN ports. This protocol is defined in IEEE 802.3ad.
LAN
Local Area Network. Refers to the Layer 2 network domain local to a given host. Packets exchanged
between two hosts on the same LAN do not require Layer 3 routing.
Layer 2 Processor
A processor in the IPS. Processes layer 2-related events. It also identifies malformed packets and
removes them from the processing path.
Logger
A component of the IPS. Writes all the log messages of the application to the log file and the error
messages of the application to the Event Store.
logging
Gathers actions that have occurred in a log file. Logging of security information is performed on two
levels: logging of events (such as IPS commands, errors, and alerts), and logging of individual IP
session information.
LOKI
Remote access, back door Trojan, ICMP tunneling software. When the c omputer is infected, the
malicious code creates an ICMP tunnel that can be used to send small payload ICMP replies.
M
MainApp
The main application in the IPS. The first application to start on the sensor after the operating system
has booted. Reads the configuration and starts applications, handles starting and stopping of
applications and node reboots, handles software upgrades.
maintenance
partition
The bootable disk partition on IDSM2, from which an IPS image can be installed on the application
partition. No IPS capability is available while the IDSM2 is booted into the maintenance partition.
maintenance
partition image
The bootable software image installed on the maintenance partition on an IDSM2. You can install the
maintenance partition image only while booted into the application partition.
major update
A base version that contains major new functionality or a major architectura l change in the product.
Malware
Malicious software that is installed on an unknowing host.
manufacturing
image
Full IPS system image used by manufacturing to image sensors.
master blocking
sensor
A remote sensor that controls one or more devices. Blocking forwarding sensors send blocking requests
to the master blocking sensor and the master blocking sensor executes the blocking requests.
MD5
Message Digest 5. A one-way hashing algorithm that produce s a 128-bit hash. Both MD5 and Secure
Hash Algorithm (SHA) are variations on MD4 and stren gthen the security of the MD4 hashing
algorithm. Cisco uses hashes for authentication within the IPSec framework. Also used for message
authentication in SNMP v.2. MD5 verifies the integrity of the communication, authenticates the origin,
and checks for timeliness.
Meta engine
Defines events that occur in a related manner within a sliding time interval. This engine processes
events rather than packets.