Firepower Signature Engines Flashcards
(15 cards)
AIC
Web traffic analysis
Atomic
ARP - layer 2 ARP protocol
IP Advanced - IPv6 Layer 3 and ICMPv6 Layer 4
IP - Layer 4 transport protocols
IPv6 - IOS vulns simulated by malformed IPv6 traffic
Fixed
Parallel regex matches - ICMP/TCP/UDP
Flood
ICMP and UDP floods
Meta
Events that occur in a related manner
Multi String
Matches several strings for one signature
Normalizer
Enforce RFC compliance
Service
Specific protocols
State
Stateful searches of strings in protocols
String
Matches a regex string based on ICMP/TCP/UDP protocol
String XL
Optimized operation of String
Sweep
Sweeps from a single host, destination ports, and multiple ports with RPC requests
Traffic Anomaly
Inspects TCP/UDP and other traffic for worms
Traffic ICMP
Analyzes nonstandard protocols such as TFN2K/LOKI/DDOS
Trojan
Analyzes traffic from nonstandard protocols such as BO2K and TFN2K