cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
671
Views
0
Helpful
2
Replies

IPS Signature updates

networker99
Level 1
Level 1

Is there a Cisco best practice for downloading IPS signature updates?, any documentation on this?, also how often are updates released?

2 Replies 2

rjaaouan
Cisco Employee
Cisco Employee

Hi,

to know all new Signature update, you can subsribe a ips-news@cisco.com distr list. You will revieve an email with all new Signature...

they will send you an email as soon as an update is availble, lik ethis:

1. Announcing the S387 Signature Update for IPS

The S387 signature update contains the following new signatures:

PLATFORM SIGID SIGNAME ENGINE SEVERITY ENABLED

5.x,6.x 6147.0 RealPlayer RealMedia Security Bypass string-tcp high false

5.x,6.x 6733.0 CA BrightStor ARCServe Backup LGServer Arbitrary File Upload string-tcp high false

5.x,6.x 6297.0 RealPlayer ActiveX Import Method Buffer Overflow meta high true

till now you need to download the signature on your compter, the upload it, or use an Autoupdate feature with the IDM.

I think Signatures are released, when there is new attack or weakness..., but you can use Anomaly Detection to detect any suspected behavior: Zero-Day detection.

Cheers

Reda

Review Cisco Networking products for a $25 gift card