IPS Signature Statuses

Hi All.
I'm struggling to find a definitive answer or reason for some of the configuration IPS signature statuses.
What does the enabled setting in a rule actually mean in relation to retired and obsolete rules?
I have lots of rules which are enabled but which are also set as retired and/or obsolete. I'm assuming from my reaserach that these are not active rules
Why are these enabled? (especially when it doesn't mean anything?)
I appreciate that retired rules can be overidden and set to active, but surely when using the defaults from Cisco the retird rules should not be enabled?
I'm really confused by the non-sensical approach of both this and MARS.
Any help would be gratefully received.
Thanks
Mark

Anybody?

Similar Messages

  • IOS IPS Signature-File

    Hi Guys,
    We have recently purchased a Cisco ISR 2921,  and on its docs it is writen that this product has a License for IOS IPS Signatrue File,  but on the product Flash Memory there is no  IOS IPS Sig-File.   and while i try to download the sig-file from Cisco, it fails.
    Can any one tell me where is an alternate way to download the sig-file ?

    900 active signatures is quite much for a system that has no dedicated IPS-ressources.
    But you can controll which and how many signatures get enabled on your router:
    In the following example I first disable all signatures and enable the ones for web-servers. So just decide which signatures you need. But don't forget to monitor your router-ressources.
    gw#conf t
    Enter configuration commands, one per line.  End with CNTL/Z.
    gw(config)#ip ips signature-category
    gw(config-ips-category)#?
    IPS signature category configuration commands:
      category  Category keyword
      exit      Exit from Category Mode
      no        Negate or set default values of a command
    gw(config-ips-category)#category ?
      adware/spyware                Adware/Spyware (more sub-categories)
      all                           All Categories
      attack                        Attack (more sub-categories)
      configurations                Configurations (more sub-categories)
      ddos                          DDoS (more sub-categories)
      dos                           DoS (more sub-categories)
      email                         Email (more sub-categories)
      instant_messaging             Instant Messaging (more sub-categories)
      ios_ips                       IOS IPS (more sub-categories)
      l2/l3/l4_protocol             L2/L3/L4 Protocol (more sub-categories)
      network_services              Network Services (more sub-categories)
      os                            OS (more sub-categories)
      other_services                Other Services (more sub-categories)
      p2p                           P2P (more sub-categories)
      reconnaissance                Reconnaissance (more sub-categories)
      releases                      Releases (more sub-categories)
      specially_licensed_signature  Specially Licensed Signature (more sub-categories)
      telepresence                  TelePresence (more sub-categories)
      uc_protection                 UC Protection (more sub-categories)
      viruses/worms/trojans         Viruses/Worms/Trojans (more sub-categories)
      web_server                    Web Server (more sub-categories)
    gw(config-ips-category)#category all
    gw(config-ips-category-action)#retire true
    gw(config-ips-category-action)#exit              
    gw(config-ips-category)#category web_server
    gw(config-ips-category-action)#?
    Category Options for configuration:
      alert-severity   Alarm Severity Rating
      enabled          Enable Category Signatures
      event-action     Action
      exit             Exit from Category Actions Mode
      fidelity-rating  Signature Fidelity Rating
      no               Negate or set default values of a command
      retired          Retire Category Signatures
    gw(config-ips-category-action)#retired false
    gw(config-ips-category-action)#exit
    gw(config-ips-category)#exit
    Do you want to accept these changes? [confirm]
    gw(config)#
    gw(config)#exit
    gw#sh ip ips configuration | s IPS Signature Status
    IPS Signature Status
        Total Active Signatures: 131
        Total Inactive Signatures: 4370
    gw#
    I didn't follow the thread and answered your first post to have less line-breaks in this post.

  • Is it really possible to revert IPS signatures from CSM

    Hi folks,
    I've been trying to revert IPS signatures that I deployed through CSM Signature policies to the older release but it doesn't seem to be working. Contrary to it Cisco's CSM guide says:
    If you later decide that you did not want to apply a signature update, you can revert to the
    previous update level by selecting the Signatures policy on the device, clicking the View
    Update Level button, and clicking Revert
    I can't imagine it is possible as the signatures are normally compiled into xml files. How would the sensor do it ?
    Eugene

    During installation a copy of files that will be replaced or updated during the installation will be copied into a backup directory.
    The CLI has a "downgrade" command that can uninstall the last update, and the backup copies will be used to replace the files being removed.
    A few things to be aware of:
    1) Old configuration will be copied back. So changes made since the update may be lost.
    2) This works only for Engine Updates and Signature Updates. Major Updates, Minor Updates, and Service Packs replace the complete operating system so there is too much data to try and make backup copies for.
    3) This works only for the last update installed. Once you've downgraded the latest one, you can't downgrade the previous one.
    4) This can be done through CLI, and now also available in CSM.
    Here are some things to check in your situation where it appears to not be working.
    Login to the sensor and execute "show ver".
    Does the history in the "show ver" output show a Signature Update package as the last update installed?
    If not then either another downgrade was previously done, or a Major Update, Minor Update, or Service Pack was the last package installed and can't be downgraded.
    If it can't be done through CSM you might try the CLI' "downgrade" command and see if it works through the CLI or if the CLI gives you an error and explanation.

  • Correct procedure to update IOS IPS signatures on 2911 router

    What is the correct procedure to update the IOS IPS signatures on an 2911 router?
    I know how to download the signatures file (eg. IOS-S556-CLI.pkg) but what is the correct way to install the update?
    Thank you in advance!

    The IPS signature package comes with a list of pre-enabled signatures, hence Cisco does not recommend enabling a lot more other signatures, especially not every single signature as documented.
    The reason why is because the package might include retired/old signatures only for references, and not every single signature is required to protect your environment because you might not have the traffic for some signatures, you might not have some end hosts that are written with specific signatures, therefore, it becomes irrelevant if you enable it.
    Typically here is how customer would enable/disable signatures:
    - Use the default signature that is enabled by Cisco (the default should fit majority of the customers).
    - Monitor it for a couple of months
    - Disable those that you don't need, and enable others if you think you require it for specific.

  • Document SIgnature Status becomes invalid after resigning

    Hi all,
    I  have a form with two Document Signature.
    When i clear and resign one of the Document Signature it status is invalid.
    Please suggest me a solution.
    Regards,
    S.V.Satish Kumar

    I tested the form you posted.  Here is what I found, but I am not completely clear on what all your script is supposed to be doing.
    Steps
    1)  I filled in the first "comment line"
    2)  I signed the first signature field
    3)  Results:  The signature was valid, the document status (see screen shot 1signature_docstatus.gif) reported the signature was valid.  The signature staus was valid as displayed in the signature panel (see screen shot 1signature_detail.gif)
    4)  I added and filled in a second "comment line"
    5)  I signed the second signature field
    6)  Results:  The first signature was valid, the second signature was valid, and the document status repored that ther were "unsigned changes" since the last signature was applied (see screen shot 2signature_docstatus.gif) The signature statuses were valid with subsequent changes made to the document as displayed in the signature panel (see screen shot 2signature_detail.gif)
    Don't confuse the "exclamation" mark icon with "Invalid", it is only a warning to inform you that changes have been made that are not "digitally signed", I suspect your some part of your script is causing this. If you want to have Acrobat\Reader display a green check mark icon, then you cannot make any changes to the document after the final signature has been applied.
    If you haven't done so, take a look at the sample I posted on your duplicate post in this forum ( http://forums.adobe.com/thread/492773?tstart=0 ).
    If a signature is "invalid" it will display a red "X" icon.
    Regards
    Steve

  • Signature status for just submitting signature and yet to validate the email

    Hi,
    I need to get a specific signature status for just submitting signature and yet to validate the email. I need to restrict the user to submit my web form with out signing in the widget. So here, while submitting the form, Im fetching the signature status via ajax though API and based on the status the web form is restricted to submit.
    But using API, I could only able to get the complete signature status(submitting signature and validating email). Is it possible to get the status of only submission and yet to validate email ?
    Thank you,

    Hi Asmusz,
    Thanks for the reply.
    I created the widget with API createEmbeddedWidget and got documentKey in return from the result. Here is the result when I tried to get the status of the document from getDocumentInfo by passing documentKey:
    object(stdClass)#75 (1) {
      ["documentInfo"]=>
      object(stdClass)#76 (10) {
        ["events"]=>
        object(stdClass)#77 (1) {
          ["DocumentHistoryEvent"]=>
          object(stdClass)#78 (8) {
            ["type"]=>
            string(7) "CREATED"
            ["actingUserIpAddress"]=>
            string(13) "123.143.44.82"
            ["actingUserEmail"]=>
            string(27) "[email protected]"
            ["comment"]=>
            NULL
            ["participantEmail"]=>
            string(27) "[email protected]"
            ["date"]=>
            string(25) "2013-12-03T05:02:23-08:00"
            ["description"]=>
            string(31) "Document created by Naveen"
            ["documentVersionKey"]=>
            string(15) "X38BTTMN4D734M3"
        ["latestDocumentKey"]=>
        string(15) "X38BTTP3X7XKK4W"
        ["locale"]=>
        string(5) "en_US"
        ["message"]=>
        NULL
        ["name"]=>
        string(19) "[DEMO USE ONLY] ew9"
        ["nextParticipantInfos"]=>
        NULL
        ["documentKey"]=>
        string(15) "X389U3WXM663X76"
        ["securityOptions"]=>
        NULL
        ["participants"]=>
        object(stdClass)#79 (1) {
          ["ParticipantInfo"]=>
          object(stdClass)#80 (8) {
            ["roles"]=>
            object(stdClass)#81 (1) {
              ["ParticipantRole"]=>
              string(6) "SENDER"
            ["status"]=>
            string(6) "WIDGET"
            ["alternateParticipants"]=>
            NULL
            ["securityOptions"]=>
            NULL
            ["company"]=>
            string(20) "NaveenTechnology"
            ["email"]=>
            string(27) "[email protected]"
            ["name"]=>
            string(11) "Naveen"
            ["title"]=>
            string(13) "Sr. Developer"
        ["status"]=>
        string(6) "WIDGET"
    and the result is the same even If the document is signed in the widget and waiting for email validation. Not sure if im in a right path to get 'WAITING_FOR_VERIFICATION' status. Please clarify.
    Thank you,

  • Signature status not coming correct during silent printing. Bug?

    Am using javascript inside my plugin to get the signature status in Acrobat 9.3.  Below is the code.
    sprintf(jsScript,"var f = this.getField('%s').signatureInfo(); event.value = f.status; ",strSigField);ASBool bRet = AFExecuteThisScript (gPDDoc, jsScript, &pReturnValue);
    This is working fine, except during slient printing.  Everytime including normal print, am getting the status as '4' i.e. signed which is correct.
    However, while printing silently in Acrobat either via code or manually by Right-clicking on the pdf in Explorer and selectting Print, am getting '1' i.e. unknown status for signed signature fields.
    Have also tried executing the menu item "Advanced->Sign & Certify->Validate All Signatures" before trying to get the status but am getting the same result.
    Please let me know if anyone else has also experienced the same issue and what is the cause/resolution of the same or this is a bug in Acrobat?

    Irosenth,
    Submitted a bug report and uploaded the sample pdf at http://www.megaupload.com/?d=Z5P8STOL.
    Let me know if any further information is required.

  • How to upgrade IPS Signature

    Can anyone help me with the steps of upgrading the IPS signature for the platform ASA SSM-20, IDS 4215, WV-SVC-IDSM-2 via IDM and IME. All the sensors are already upgraded with Engine E4 with signature S480.
    Can I upgrade the signature directly from S480 to S507? Please let me know the file which I need to download. Is there any impact while updating the signture like reboot?

    Hi Gangadaran,
    We can apply the same package on all the mentioned platforms. It can be applied to all below platforms:
    - IPS-42xx Cisco Intrusion Prevention System (IPS) sensors
    - IDS-42xx Cisco Intrusion Detection System (IDS) sensors (except the IDS-4220, and IDS-4230)
    - WS-SVC-IDSM2 series Intrusion Detection System Module (IDSM2)
    - NM-CIDS IDS Network Module for Cisco 26xx, 3680, and 37xx Router Families.
    - ASA-SSM-10 Cisco ASA Advanced Inspection and Prevention Security Services Module (Requires ASA)
    - ASA-SSM-20 Cisco ASA Advanced Inspection and Prevention Security Services Module (Requires ASA)
    - ASA-SSM-40 Cisco ASA Advanced Inspection and Prevention Security Services Module (Requires ASA)
    - AIM-IPS Cisco Advanced Integration Module for ISR Routers
    Refer the readme for all details:
    http://www.cisco.com/web/software/282549755/37074/IPS-sig-S507.readme.txt
    All the best!!
    Thanks,
    Prapanch

  • How to convert Cisco IPS signatures to a MARS events - no keyword search

    I am trying to run a scheduled report looking for the new Microsoft exploit under the IPS S411 release, SIGID 19339.0 and I am trying to form the query looking for the event this falls under without using a keyword search on the SIGID. Does anyone know how to correlate an IPS signature to a MARS event?
    Thanks,
    Mike

    With the help of On-box local event correlation technology you can correlate. On-box local event correlation technology not only enables detection, but actually blocks multi-event attacks and malware in real time, complementing security incident management software such as the Cisco Security Monitoring, Analysis, and Reporting System (Cisco Security MARS) that correlate events across multiple devices.
    Integrates with the Cisco Security Manager to correlate security events with the configured firewall rules and intrusion prevention system (IPS) signatures that can affect the security event

  • Where do IPS signature save at?

    Hi
    i successfully load the IOS IPS package into the router, verify via CLI and CCP the IPS signature did compile on the router. (advanced mode, around 588 signature is active)
    but it went gone (happened twice), i just want to ensure few things
    1. i did shut down my router, and migrate to production site, would it cause by the power off / on then IPS signature missing?
    2. i did remove the "ip ips iosips in/out" command that previous apply at my interface, would this cause the IPS disable and gone?
    just counldn't figure out why now my router only have 3 signature only..
    thanks

    1. Please use the doc below for reference on how to configure IOS-IPS on the router. I will try to answer your questions using this document.
    http://tools.cisco.com/squish/9Be6a
    2. You will see in step 2.1 we create directory on flash to store all the signature files and configurations.
    e.g:
    mkdir
    router#mkdir ips
    Create directory filename [ips]
    Created dir flash:ips
    3. In step 4.2 , we configure IPS signature storage location by referencing the directory we created above.
    e.g:
    ip ips config location flash:
    router(config)#ip ips config location flash:ips
    This is where the signature files will be stored.
    4. In step 5.1 we copy the signature files to the router.
    e.g:
                 router#copy ftp://cisco:[email protected]/IOS-S310-CLI.pkg idconf
    Loading IOS-S310-CLI.pkg !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
    [OK - 7608873/4096 bytes]
    The idconf command compiles the signature after the file is copied.
    5. If all the above steps are done correctly, you should see the following files in flash:
    router#dir ips
    Directory of flash:/ips/
    7 -rw- 203419 Feb 14 2008 16:45:24 -08:00 router-sigdef-default.xml  <----Contains factory default signature definitions.
    8 -rw- 271 Feb 14 2008 16:43:36 -08:00 router-sigdef-delta.xml
    9 -rw- 6159 Feb 14 2008 16:44:24 -08:00 router-sigdef-typedef.xml
    10 -rw- 22873 Feb 14 2008 16:44:26 -08:00 router-sigdef-category.xml
    11 -rw- 257 Feb 14 2008 16:43:36 -08:00 router-seap-delta.xml
    12 -rw- 491 Feb 14 2008 16:43:36 -08:00 router-seap-typedef.xml
    64016384 bytes total (12693504 bytes free)
    6. Make sure you do a 'Router#write memory' before you reload the router. This way the configuration done gets stored and is preserved after reboot.
    Also make sure your configuration register on the router is correctly set to 0x2102.
    Sid Chandrachud
    TAC security solutions

  • IOS IPS Signature Updates

    Hi,
    Is it possible to update signatures for IOS IPS or do we need to update the IOS to get more signatures?
    Thanks and rgds
    Rajesh

    hi,
    if you have cisco sdm, then it would be easy to update your IOS IPS signatures. You may need to upgrade IOS of the router only when the ips signature requires you to do it.

  • Tune IPS Signature

    Hi,
    I want to to tune IPS signature so that it can make exception of ip addresses.
    the signature is 13004 (this is UDP scan signature) i have ciscoworks in my network which scan the network using UDP i dont want to disable the signature i just want to add the ip address of ciscoworks to safe list ( if it exists) i have configured the alert to be sent to my email and i got alot of those emails which says
    high 13004-0 "AD - External UDP Scanner" x.y.z.w/src_port(*) 0.0.0.0/dest_port(*)
    thanks

    Alakabeer -
    You want to configure an Event Action Rule for this signature with the IP address of your Ciscoworks host in the Event Action Variable:
    http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_event_action_rules.html#wp1032319
    - Bob

  • Hiding subflows and Signature Status

    Hi There,
      Hiding subFlows in PreSign is causing the signature status to display "At lease one signature requires validation...." instead of the valid green tick mark. When I right cick and validate again the display shows the green tick mark. Please help.
    Regards,
    RT

    Hi There,
      Hiding subFlows in PreSign is causing the signature status to display "At lease one signature requires validation...." instead of the valid green tick mark. When I right cick and validate again the display shows the green tick mark. Please help.
    Regards,
    RT

  • Filtering IPs on a IDS/IPS signature

    Forgive me, I am pretty green when it comes to manipulting IDS/IPS signatures.
    Is there a way to filter an IP or subnet from a IDS/IPS signature?
    Senario:
    We have 2 ASAs with IPS modules and 2 4260 IDS's, we use IPS Manager Express 6.1 to manage them. I keep getting a mail server that is triggering signature 5748-x because its sending a helo verb instead of a noop. This is fine for this paticular mail server. So i would like to remove its IP or filter its IP from the signature so when this happens the signature doesnt fire. However I dont want to disable the signature in case it happens somewhere else.
    any help is greatly appreciated.
    e-

    It's not really too bad. I would encourage you to read still though;-)
    Each signature can be configured with any number of actions. by default, a lot of them have the "product alert" action.
    event action filters are basically a way to suppress all or some actions based on various criteria, like sigid and source (attacker) ip address. I've attached an example.

  • Anyone else notice IPS Signature 1548/0 firing frequently?

    Hello.
    We have seen IPS Signature 1548/0-"Microsoft Offic Picture Managed Memory Corruption" trigger frequently on image files downloaded from IP addresses associated with Microsoft, in the range of 207.46.0.0/16.  This has happened for several different customers we manage and I'm wondering if anyone else has seen this new signature fire frequently.
    It looks to me that this signature has not been tuned correctly by Cisco because in every case the "Source" IP in the alert was from Microsoft.  Just wondering if anyone else has seen this too.
    Jon.

    The signature will be disabled and retired in an upcoming signature update.  The new signature will have an updated benign triggers section to reflect that this sig may trigger on potentially benign traffic. In the meanwhile , please feel free to disable and retire this signature. Let me know if you have any additional questions.

Maybe you are looking for

  • Error while creating the PO - E BBP_PD  047

    Hi, While creating the service PO and posting, we are facing the error message "E BBP_PD  047 Indicate tax domicile key". The Supplier has registered tax domicile. Kindly tell me any one what is the reason for this kind of error. Regards, Fernando.

  • *@#% CSS ...

    Hi guys ... I have struggle for quite some time now, with the formatting of dynamic text i Flash. Now I face the challenge of having inline formatting of specific words and headlines and so on. The only solution as far as I see it, is CSS formatting.

  • Update iPad2 from 4.3.5 to iOS 7 error message 4000 or 11 (using iTunes 11.3, MAC OS X 10.7.5)

    I want to update my iPad2 from 4.3.5 to iOS 7. But after approx. 30 min. I get error message 4000 or sometimes 11. I have updated iTunes to 11.3, MAC OS X 10.7.5 and disabled the firewall. I have also tried the tiny umbrella method, but tiny umbrella

  • Really Frusterating, help please

    I havent used my ipod nano in a while, but when i connect it, nothing happens, when i turn on itunes, occasionally, the ipod will say "do not disconnect" and my ipod file comes up, after a few seconds it dissapears. When i try to upgrade, it says inv

  • Personal - Looking into SAP Functional side

    Hello Friends, I have experience on SAP XI/PI over 4 years...moreover i would like to learn / work SAP functional. I preferred SAP SCM would be the best opportunity to learn and my education background is MCA. Could you please suggest whether this de