Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IPS Signature updates

Is there a Cisco best practice for downloading IPS signature updates?, any documentation on this?, also how often are updates released?

2 REPLIES
Cisco Employee

Re: IPS Signature updates

Hi,

to know all new Signature update, you can subsribe a ips-news@cisco.com distr list. You will revieve an email with all new Signature...

they will send you an email as soon as an update is availble, lik ethis:

1. Announcing the S387 Signature Update for IPS

The S387 signature update contains the following new signatures:

PLATFORM SIGID SIGNAME ENGINE SEVERITY ENABLED

5.x,6.x 6147.0 RealPlayer RealMedia Security Bypass string-tcp high false

5.x,6.x 6733.0 CA BrightStor ARCServe Backup LGServer Arbitrary File Upload string-tcp high false

5.x,6.x 6297.0 RealPlayer ActiveX Import Method Buffer Overflow meta high true

till now you need to download the signature on your compter, the upload it, or use an Autoupdate feature with the IDM.

I think Signatures are released, when there is new attack or weakness..., but you can use Anomaly Detection to detect any suspected behavior: Zero-Day detection.

Cheers

Reda

358
Views
0
Helpful
2
Replies