The Importance of Signatures Updates

Traditionally, IPS and IDS systems depend on signatures to operate. Because of this, it is extremely important to tune the IPS/IDS device accordingly and to develop policies and procedures to continuously update the signatures. The Cisco IPS software allows you to automatically download signatures from a management station. Signature updates are posted to Cisco.com almost on a weekly basis. In Chapter 2, you learned about the Cisco Security Center (historically named mySDN or my Self Defending Network). This is an excellent resource to obtain information about the latest IPS signatures and other security intelligence information.

NOTE The Cisco Security Center site is http://www.cisco.com/security.

The Cisco Security Center provides up-to-date security intelligence data, in addition to detailed IDS/IPS signature information.

Although the IPS sensors can work without a license key, you must have a license key to obtain signature updates from Cisco.com. To obtain a license key, you must have a Cisco Service for IPS service contract. For more information, go to http://www.cisco.com/go/ license.

The Cisco IPS Device Manager (IDM) is a web-based configuration utility used to manage individual IPS sensors, Catalyst 6500 IPS modules, and the Advanced Inspection and Prevention Security Services Module (AIP-SSM) for the Cisco ASA. You can configure the IPS device via IDM to automatically obtain and install signatures from an FTP or SCP server.

NOTE You cannot automatically download service pack and signature updates from Cisco.com.

You need to download service packs and signatures updates from Cisco.com to an FTP or SCP server. Then you can configure your IPS device to access the files on your server. You can also use the Cisco Security Manager IPS Manager Console (IPSMC) to manage your IPS devices. You can configure IPSMC to automatically download the signature updates and service packs from Cisco.com and then install them in your IPS devices. For more information about IPSMC, go to http://www.cisco.com/go/security.

Complete the following steps to configure IDM to automatically download signatures from your FTP or SCP server.

Step 1 Log in to IDM with an administrator account and navigate to Configuration > Auto Update.

Step 2 Select the Enable Auto Update check box.

Step 3 Enter the IP address of the remote server where the signature update or service packs are saved.

Step 4 Select either FTP or SCP for your transport mechanism/server type.

Step 5 Enter the path to the directory on the remote server where the updates are located in the Directory Path.

Step 6 Enter the username and password of the account in your FTP or SCP server.

Step 7 You can configure the IPS device to check for updates hourly or on a weekly basis. If you want your IPS device to check for updates hourly, check the Hourly check box. Then enter the time you want the updates to start and the hour interval at which you want the IPS device to contact your remote server for updates. The IPS sensor checks the directory you specified for new files in your server. Only one update is installed per cycle even if there are multiple available files.

Step 8 Check the Daily check box if you want the IPS device to automatically check for updates on a daily basis. Then enter the time you want the updates to start and check the days you want the IPS device to check for updates in your SCP or FTP server.

Step 9 To save and apply your configuration, click Apply.

Continue reading here: Anomaly Detection Within Cisco IPS Devices

Was this article helpful?

0 0