Owner's Manual

436
IDS Rules
The Adaptive Services PIC (AS PIC) supports a limited set of intrusion detection services (IDS) to
perform attack detection. It detects various types of denial of service (DoS) and directed denial of
service (DDoS) attacks. It also detect attempts at network scanning and probing. Finally, it detects
anomalies in traffic pattern, such as sudden bursts or decline in bandwidth. It redirects attack
traffic to a collector for analysis.
This driver also supports IDS as a group operation. Consult the following for descriptions of fields
in the group operations screen.
Figure 13-15. IDS Rules
Click
Add
(or select an existing rule and click
Edit
) to open the rules editor. You can also click
Delete
to remove a selected rule at the top of this screen. Click
Export
to save a description of the
listed items to a file. Once you have edited a rule, click
Apply
to accept your edits for the list, or
click
Cancel
to abandon them. The editor has the following fields:
-
Rule Name
An identifier for the stateful firewall ruleset.