Steps to create the attack definition for this example:
In the Custom Attack Editor, click
.The New Custom Attack interface opens.
Select one of the options from the State drop-down menu.
You can specify a name such as "CGI: Trillion or Trilliant" as the Name.
The letters "UDS" (user-defined signature) are appended to the front of the name upon completion; thus, this attack appears as "UDS-CGI: Trillion or Trilliant" in the Custom Attack Editor, as well as the attack database when you save in the Manager server.
Type a description for your attack. This area can be used for your notes or other specific information pertinent to your new attack.
You can select Medium as the Severity because this example scenario does not necessarily involve malicious activity.
Select Advanced Protection Options/Web Application Server Protection as the Protection Category.
Select URL from the Detection Type drop-down menu for the attack.
Enter the URL that is to be detected, then click Add.
In the Matching Criteria section, the protocol is automatically selected as http.
When you subsequently save this attack definition in the Manager server, it will be part of every rule set which includes Medium-severity, HTTP attacks (must match both severity and protocol).
Attack details configuration is complete. Continue to create signature.