Current Issue


Table of contents

CD-ROM

Sys Admin and The Perl Journal CD-ROM version 12.0

Version 12.0 delivers every issue of Sys Admin from 1992 through 2006 and every
issue of The Perl Journal from 1996-2002 in one convenient CD-ROM!

Order now!

Sys Admin Magazine > Archives > 2007 > June 2007
SysAdminMag.com

Automating Signature Updates for Cisco IPS/IDS Sensors

Lisa Hamet Bernard

As the variety, sophistication, and sheer volume of server and network threats increase, so does the demand for Intrusion Prevention Systems/Intrusion Detection Systems (IPS/IDS). These network devices recognize malicious traffic, including viruses, worms, and various traffic patterns indicative of hacking techniques targeting both operating systems and applications.

The network filtering to determine the presence of such events is based upon a set of " signatures" , packet sequences that define each intrusion. When an event is detected, an alert is triggered, and in the case of IPS devices, traffic from the offending IP address is immediately blocked. But, like anti-virus software on PCs, IPS/IDS devices are only as effective as the latest signatures of which they are aware. Security software companies rush to fingerprint new threats as soon as they are discovered and release signature updates that can detect these threats. Systems and network administrators must be just as proactive by installing these updates as soon as they are available.

Cisco Systems, Inc. offers a family of IPS/IDS sensors -- both standalone appliances and switch/router modules. Cisco releases regular signature update files as new threats are discovered, which can vary in frequency from daily to every few weeks. Updates are made available on Cisco's FTP site and announced via a mailing list to which anyone with a valid CCO (Cisco Connection Online) account may subscribe. The operating system includes an automatic upgrade utility feature that installs an update from a local file server on a configurable schedule. However, automating signature downloads to the local file server requires purchasing either Cisco Security Manager (CSM) or its predecessor, CiscoWorks VPN/Security Management System (VMS).




MarketPlace

Flowcharts from C/C++ code -- Free trial download
Understand C/C++ code in less time. A new team member ? Inherited legacy code ? Get up to speed faster with Crystal Flow for C/C++. Code-formatting improves readability. Flowcharts are integrated with code browser. Export flowcharts to Visio.

Automate Software Builds with Visual Build Pro
Easily create an automated, repeatable process for building and deploying software.

WinDev 12 - Powerful IDE
Develop 10 times faster ! ALM, IDE, .Net, RAD, 5GL, Database, 5GL, 64-bit, etc. Free Express version

Web based bug tracking - AdminiTrack.com
AdminiTrack offers an effective web-based bug tracking system designed for professional software development teams.

Wanna see your ad here?