Anomaly Detection Within Cisco IPS Devices
When you configure a Cisco IPS device running Versions 6.x and later with anomaly detection services, the IPS device initially goes through a learning process. This is done to configure a set of policy thresholds based on the normal behavior of your network. Three different modes of operation take place when an IPS device is configured with anomaly detection:
• Learning mode
• Detect mode
• Inactive mode
The initial learning mode is performed over a period of 24 hours, by default. The initial baseline is referred to as the knowledge base (KB) of your traffic.
TIP The IPS sensor does not detect attacks during the initial learning phase. If you experience an attack during this period, your results will not reflect a baseline of normal network behavior. This is an important point to take into consideration. Depending on your environment, you may want to have the IPS device in learning mode longer than the default 24 hours because this is a configurable value. Do not initially enable your IPS device with anomaly detection over a weekend if your organization operates mostly during normal business hours and days. This is a huge mistake that many people make.
To configure the IPS sensor using IDM to start the learning mode, go to Configuration > Policies > Anomaly Detections > ad0 > Learning Accept Mode and select the Automatically accept learning knowledge base check box. In that section, you can also specify the learning period length.
After the learning process, a KB is created that replaces the initial KB. The IPS device then automatically goes into detect mode. Any traffic flows that violate thresholds in the KB trigger the IPS device to generate alerts. The IPS device also keeps track of gradual changes to the KB that do not violate the thresholds and adjusts its configuration.
You can turn off the anomaly detection functionality on your IPS device. This is called being in inactive mode. In certain circumstances, this is needed. An example is when you have an asymmetric environment and the IPS device gets traffic from different directions, causing it to operate incorrectly.
NOTE The traffic anomaly engine in Cisco IPS devices uses nine anomaly detection signatures covering TCP, UDP, and other protocols. Each signature has two subsignatures: one for the scanner and the other for the worm-infected host. All of these signatures are enabled by default, and they are in the 13000 range.
Similarly to the Cisco TAD XT, the anomaly detection feature in Cisco IPS devices uses zones. The purpose of configuring zones is to make sure that you do not have false positives and false negatives. A zone is a set of destination IP addresses. Three different zones exist:
• Internal: You configure this zone with the IP address range of your internal network.
• Illegal: You configure this zone with IP address ranges that should never be seen in normal traffic. Here you should use unallocated IP addresses or bogon IP addresses.
• External: This is the default zone. By default, it has the Internet range of 0.0.0.0255.255.255.255.
To configure the Internal zone in your IPS device using IDM, complete the following steps:
Step 1 Navigate to Configuration > Policies > Anomaly Detections > ad0 > Internal Zone. The Internal Zone tab appears.
Step 2 Click the General tab.
Step 3 Select the Enable the Internal Zone check box.
Step 4 Enter your internal subnets/IP address range in the Service Subnets field. IDM also allows you to configure protocol and other specific thresholds.
NOTE For more information on how to configure other thresholds and anomaly detection functionality, refer to the Cisco IPS configuration guides located at http://www.cisco.com/ univercd/cc/td/doc/product/iaabu/csids/csids13/idmguide/index.htm.
Continue reading here: Traceback
Was this article helpful?