Intrusion Prevention Technologies

This topic provides an explanation of IPS technologies, attack responses, and monitoring options.

Cisco IOS IPS Attack Responses

• Deny Attacker Inline

• Produce Alert

• Deny Connection Inline

• Produce Verbose Alert

• Deny Packet Inline

• Request Block Connection

• Log Attacker Packets

• Request Block Host

• Log Pair Packets

• Request SNMP Trap

• Log Victim Packets

• Reset TCP Connection

— — - —I

When an IPS sensor, configured with Cisco IOS IPS 5.0 or later, detects malicious activity, it can choose from any or all of these actions:

■ Deny Attacker Inline: This action terminates the current packet and future packets from this attacker address for a specified period of time. The sensor maintains a list of the attackers currently being denied by the system. You can remove entries from the list or wait for the timer to expire. The timer is a sliding timer for each entry. Therefore, if attacker A is currently being denied, but issues another attack, the timer for attacker A is reset and attacker A remains on the denied attacker list until the timer expires. If the denied attacker list is at capacity and cannot add a new entry, the packet is still denied.

■ Deny Connection Inline: This action terminates the current packet and future packets on this TCP flow.

■ Deny Packet Inline: This action terminates the packet.

■ Log Attacker Packets: This action starts IP logging on packets that contain the attacker address and sends an alert. This action causes an alert to be written to the Event Store, even if the Produce Alert action is not selected.

■ Log Pair Packets: This action starts IP logging on packets that contain the attacker and victim address pair. This action causes an alert to be written to the Event Store, even if the Produce Alert action is not selected.

■ Log Victim Packets: This action starts IP logging on packets that contain the victim address and sends an alert. This action causes an alert to be written to the Event Store, even if the Produce Alert action is not selected.

■ Produce Alert: This action writes the event to the Event Store as an alert.

5-12 Securing Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.

■ Produce Verbose Alert: This action includes an encoded dump of the offending packet in the alert. This action causes an alert to be written to the Event Store, even if the Produce Alert action is not selected.

■ Request Block Connection: This action sends a request to a blocking device to block this connection.

■ Request Block Host: This action sends a request to a blocking device to block this attacker host.

■ Request SNMP Trap: Sends a request to the notification application component of the sensor to perform Simple Network Management Protocol (SNMP) notification. This action causes an alert to be written to the Event Store, even if Produce Alert action is not selected.

■ Reset TCP Connection: This action sends TCP resets to hijack and terminate the TCP

flow.

Note The Reset TCP Connection action can be used in conjunction with deny packet and deny flow actions. However, deny packet and deny flow actions do not automatically cause TCP reset actions to occur.

© 2006 Cisco Systems, Inc. Securing Networks with Cisco IOS IPS 5-13

Was this article helpful?

0 0
The Ultimate Computer Repair Guide

The Ultimate Computer Repair Guide

Read how to maintain and repair any desktop and laptop computer. This Ebook has articles with photos and videos that show detailed step by step pc repair and maintenance procedures. There are many links to online videos that explain how you can build, maintain, speed up, clean, and repair your computer yourself. Put the money that you were going to pay the PC Tech in your own pocket.

Get My Free Ebook


Post a comment