Skip to Main Content
SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide: Exam 500-285
book

SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide: Exam 500-285

by Todd Lammle, Alex Tatistcheff, John Gay
October 2015
Intermediate to advanced content levelIntermediate to advanced
432 pages
9h 55m
English
Sybex
Content preview from SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide: Exam 500-285

Chapter 13 Creating Snort Rules

THE SSFIPS EXAM TOPICS COVERED IN THIS CHAPTER INCLUDE THE FOLLOWING:

  • ✓ 9.1 Be familiar with the options used to create Snort rules inside the Cisco NGIPS

In this chapter, we’re going to focus exclusively on the fundamentals of Snort rules, detailing their structure, syntax, and options. We’ll also explore how Snort performs rule optimization for better performance and show you how rule matching takes place internally.

The core of the FireSIGHT System’s intrusion detection capability is the IPS detection engine, which includes the preprocessor and the IPS rule base. Once the IPS engine initializes, the rule structures initialize and begin building decision trees by grouping rules based on things like destination ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

CCIE Security v4.0 Practice Labs

CCIE Security v4.0 Practice Labs

Natalie Timms
CCNA Data Center DCICT 200-155 Official Cert Guide

CCNA Data Center DCICT 200-155 Official Cert Guide

Navaid Shamsee, David Klebanov, Hesham Fayed, Ahmed Afrose, Ozden Karakok

Publisher Resources

ISBN: 9781119155034Purchase book