Steps to add the condition to the example signature:
Condition 1 is added automatically with the URL.
Click Condition 1 so that it is highlighted.
Adding Conditions.png)
Click
in the Signature Details section.The Add AND Comparison dialog opens.
Configure Comparison window.png)
For this example, select String Pattern Match from the Comparison Type drop-down list.
Select http from the Protocol List.
Because you selected HTTP, the Custom Attack Editor displays the HTTP-specific protocol fields on the following screen.
Configure the fields for the comparison you have chosen.
For this example, specify req-uri-path for the Protocol Field. This specifies that the Sensor should search in the URI of the request packet.
Select get as the http-request-method.
From the drop-down list in the Regex Details section, select the Operator as Equals which means that the comparison criteria has to be equal to the string pattern entered.
In the Text to Match text box, type the pattern to match using the Regular Expression Language rules.
The pattern to match is "private.exe". You must add a backward slash (\) before the dot (.) to escape the dot character so that it is properly interpreted. The final string should appear as private\.exe.
Adding the string pattern to match.png)
Click
to verify that your expression is valid, and that the appropriate pattern is represented.Click Save.
Your comparison appears under Condition1.