IDPS signatures describe the characteristic features of network vulnerabilities. They are added to IDPS profiles and used in firewall rules for intrusion detection and network protection.
IDPS signatures are created by UserGate developers and added automatically to the system library when the correspondent license is present. You can create custom signatures and add them to the IDPS signature library.
For each signature, you can individually configure an action to take, logging, and saving to a PCAP file as well as enable/disable the signature. If you have modified the settings of a system IDPS signature created by UserGate, you can restore the defaults by going to Libraries ➜ IDPS signatures, selecting the signature in the list, and click Restore default.
To create a custom IDPS signature, go to Libraries ➜ IDPS signatures and click Add. After that, specify the signature properties and describe its characteristic features using the UASL syntax. Fill in the following fields:
Name |
Description |
---|---|
Enabled |
Signature on/off indicator. |
Id |
The ID of a signature group. |
Name |
The name of the signature. |
Description |
Signature description. |
Threat level |
Threat level defined by the signature. The following values are defined:
|
Class type |
The signature class determines the attack type that is detected using this signature. In addition, it determines the general events that are not related o the attack but can be relevant in certain cases; e.g., detecting the establishment of a TCP session. The class list (can be extended):
|
Category |
A signature category is a group of signatures that have common parameters. The list of categories (can be extended):
|
Signature operating system |
The operating system for which this signature is developed.
|
CVE |
Vulnerability ID according to the CVE registry. |
BDU |
Vulnerability ID according to the BDU registry. |
URL |
Optional link to a resource with the description of the vulnerability. |
UASL |
Description of the signature's features using the UASL syntax. |
General Settings |
|