03-24-2009 05:42 AM - edited 03-10-2019 04:33 AM
Is there a Cisco best practice for downloading IPS signature updates?, any documentation on this?, also how often are updates released?
03-26-2009 02:17 AM
Hi,
to know all new Signature update, you can subsribe a ips-news@cisco.com distr list. You will revieve an email with all new Signature...
they will send you an email as soon as an update is availble, lik ethis:
1. Announcing the S387 Signature Update for IPS
The S387 signature update contains the following new signatures:
PLATFORM SIGID SIGNAME ENGINE SEVERITY ENABLED
5.x,6.x 6147.0 RealPlayer RealMedia Security Bypass string-tcp high false
5.x,6.x 6733.0 CA BrightStor ARCServe Backup LGServer Arbitrary File Upload string-tcp high false
5.x,6.x 6297.0 RealPlayer ActiveX Import Method Buffer Overflow meta high true
till now you need to download the signature on your compter, the upload it, or use an Autoupdate feature with the IDM.
I think Signatures are released, when there is new attack or weakness..., but you can use Anomaly Detection to detect any suspected behavior: Zero-Day detection.
Cheers
Reda
03-26-2009 02:47 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide