Hi,
I want to create custom ips signature. I can create signature using static pattern but I don't know how I can create using dynamic pattern. Pattern can be change but I want to block if I catch same pattern in time. Aynbody know how I can create custom ips signature using dymanic pattern?
Thank you
Hi @AEK
F-SBID( --attack_id 9236; --name "S1-AP.signature"; --severity high; --protocol 132; --pattern "|00 00 00 12|"; --pattern "|09 99|"; --rate 15,60;)
In this example I can catch staticly. But --pattern "|09 99|" can be change and I don't know all the patterns. I want to block when I catch same pattern in time.
Hope this helps:
Regular expressions should conform to the Perl Compatible Regular Expression (PCRE) standard. See pcre for syntax details.
Created on 04-03-2024 03:37 AM Edited on 04-03-2024 03:38 AM
Thank you
I know that document but it does not have the answer to my question
chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/f21167b4-200c-11e9-b6f6-f8bc12...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.