rjaaouan Thu, 03/26/2009 - 02:17
User Badges:
  • Cisco Employee,

Hi,


to know all new Signature update, you can subsribe a [email protected] distr list. You will revieve an email with all new Signature...


they will send you an email as soon as an update is availble, lik ethis:


1. Announcing the S387 Signature Update for IPS


The S387 signature update contains the following new signatures:


PLATFORM SIGID SIGNAME ENGINE SEVERITY ENABLED

5.x,6.x 6147.0 RealPlayer RealMedia Security Bypass string-tcp high false

5.x,6.x 6733.0 CA BrightStor ARCServe Backup LGServer Arbitrary File Upload string-tcp high false

5.x,6.x 6297.0 RealPlayer ActiveX Import Method Buffer Overflow meta high true


till now you need to download the signature on your compter, the upload it, or use an Autoupdate feature with the IDM.


I think Signatures are released, when there is new attack or weakness..., but you can use Anomaly Detection to detect any suspected behavior: Zero-Day detection.


Cheers

Reda

Actions

This Discussion