TMS zl Management and Configuration Guide ST.1.1.100430
6-20
Intrusion Detection and Prevention
Configure IDS/IPS
■ DoS
• AnalogX Web server Denial of Service Vulnerability
• Apache scoreboard shared memory and DoS attacks
• mstream agent to handler DDOS
• mstream handler ping to agent DDOS
■ Backdoor
• Acid Battery
• Meet the Lamer
• Back Orifice
•AOL Admin
•Alvgus
•Ruler
Configure IDS/IPS
When you use the TMS zl Module as an IDS (required for monitor mode), you
can configure:
■ Protocol anomaly detection settings
■ Port maps
■ IDS signatures that are used to perform checks
■ Session inspection
When you use the TMS zl Module as an IPS, you can configure:
■ Protocol anomaly detection settings
■ Port maps
■ IPS signatures that are used to perform checks
■ Action that the TMS zl Module takes if threats are detected
■ Session inspection