Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

"stick" and "snot"

Does Cisco IDS software has any countermeasure against this kind of tool ?

Thanks and Regards,

Bruno Fernandes

1 REPLY
Bronze

Re: "stick" and "snot"

We have included protection against these forms of attacks with configurable summarization of alarm events. If the sensor receives too many of the same alarm in a given interval, it will enter into a summarization mode, only reporting the number of alarms in the interval rather all the individual alarms. This is the short explanation due to considerable configurability of the alarm summarization, but the sensor does have self-preservation mechanisms to protect itself and the mgmt. consoles from these attacks.

97
Views
0
Helpful
1
Replies