Create IPS Signature Dynamic Group
You are here: Security Services > IPS > Signatures.
Create a dynamic attack group to select its members based on the specified filters in the group. The list of attacks is updated (added or removed) automatically when a new signature database is used.
To create an IPS signatures dynamic group:
Field |
Action |
---|---|
Name |
Name must be a string beginning with a letter or underscore and consisting of letters, numbers, dashes and underscores; 250-character maximum. |
Filter Criteria |
|
Attack prefix |
Select one or more values from the list for the attack name prefix match. |
Severity |
Select one or more severity values from the list to add attack objects based on the attack severity levels (critical, info, major, minor, or warning).
|
Service |
Select one or more service values from the list to add attack objects based on the attack service. For example, BGP, FTP, and HTTP. |
Category |
Select one or more category values from the list to add attack objects based on the category. |
Recommended |
Select one of the following filter:
|
Direction |
Select one or more direction values from the list:
|
Expression |
Select one of the following expressions from the list:
|
Performance |
Select one or more performance values from the list:
|
False positives |
Select one or more false positives value from the list:
|
Attack type |
Select Anomaly or Signature attack type from the list. If you choose None, no action will be taken. |
Attacks |
Select Excluded or Not Excluded from the list to check the signatures that are part of the database updates. If you choose None, no action will be taken. |
CVSS score |
Select Greater than or Less than from the list to specify the Common Vulnerability Scoring System (CVSS) score of the attack. CVSS score of the attack is a free and open industry standard for assessing the severity of computer system security vulnerabilities. CVSS attempts to assign severity scores to vulnerabilities allowing responders to prioritize responses and resources according to threats. |
Greater than |
Set to match the CVSS score greater than the value specified. Range: 0 through 10 |
Less than |
Set to match the CVSS score lesser than the value specified. Range: 0 through 10 |
Age of attack |
Select Greater than or Less than from the list to specify the age of the attack. |
Value |
Set to match when age of attack in terms of years is greater than or less than the specified value (years). Range: 1 through 100. |
File type |
Select the file type from the list that the attack targets. For example, HTML and PDF. |
Vulnerability type |
Select the vulnerability type for IPS from the list that indicates which applications are weak and can be manipulated. The vulnerability type is reported for fixing these vulnerabilities. |
Vendor |
Group attacks specific to the product of a vendor. You can add, modify, or delete a vendor. To add a vendor to the dynamic group:
To edit a vendor, select it and click the pencil icon. To delete a vendor, select it and click the delete icon. |