This chapter is from the book
Summary
This chapter described how intrusion detection system (IDS) and intrusion prevention system (IPS) technology embedded in Cisco host- and network-based IDS and IPS solutions fight Internet worms and viruses in real time. More precisely, you have learned how
- A signature is a set of rules that an IDS and an IPS use to detect typical intrusive activity.
- To use Cisco SDM to configure Cisco IOS IPS on the router or security device, choose Configure > Intrusion Prevention > Create IPS in Cisco SDM and click the Launch IPS Rule Wizard button.
- Cisco IOS IPS combines existing Cisco IDS and IPS product features.
- To configure Cisco IOS IPS on the router or security device, click the Launch IPS Rule Wizard button in Cisco SDM.
- Cisco IOS IPS prevents intrusion by comparing traffic against the signatures of known attacks.
- Cisco IOS IPS alarms are communicated using SDEE and syslog.
- The command show ip ips all displays all the available IPS information.
References
For additional information, refer to these resources:
- Cisco Systems, Inc. Cisco Intrusion Prevention System: Introduction, http://www.cisco.com/go/ips
- Cisco Systems, Inc. Cisco Security Monitoring, Analysis and Response System: Introduction, http://www.cisco.com/go/mars
- Cisco Systems, Inc. Cisco Security Agent: Introduction, http://www.cisco.com/go/csa
- Cisco Systems, Inc. Cisco Intrusion Detection System Event Viewer 3DES Cryptographic Software Download, http://www.cisco.com/cgi-bin/tablebuild.pl/ids-ev
- Cisco Systems, Inc. Cisco IOS Intrusion Prevention System (IPS): Cisco IOS IPS Supported Signature List in 4.x Signature Format, http://www.cisco.com/en/US/partner/products/ps6634/products_white_paper0900aecd8039e2e4.shtml
- Cisco Systems, Inc. Software Download: Cisco IOS IPS, http://www.cisco.com/cgi-bin/tablebuild.pl/ios-sigup
- Cisco Systems, Inc. Software Download: Cisco IDS Management Center - Version 4.x Signature Updates, http://www.cisco.com/cgi-bin/tablebuild.pl/idsmc-ids4-sigup
- Cisco Systems, Inc. Cisco IOS Security Configuration Guide, Release 12.4: Configuring Cisco IOS Intrusion Prevention System (IPS), http://tinyurl.com/3ufo6j
- Cisco System, Inc. Tools & Resources: Software Download, Cisco IOS IPS Signature Package for SDM 2.4, http://www.cisco.com/cgi-bin/tablebuild.pl/ios-v5sigup-sdm
- Cisco System, Inc. Cisco Security Center, http://tools.cisco.com/security/center/home.x
- Cisco Systems, Inc. Cisco IOS Security Configuration Guide, Release 12.4: Configuring Cisco IOS Intrusion Prevention System (IPS), http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a00804453cf.html
- SearchSecurity.com. http://searchsecurity.techtarget.com/