After you create the attack definition, you create the signature for the attack.
Task
- Click Signature-<signature name> tab.
- (Optional) Clear the Name and type a new name for your signature.
- For this example, you can leave the Benign Trigger Probability (BTP) and Target Host Architecture with the default values.
- This example is to search for a string in the HTTP URI. So, select Request Packets as the Detection Window.
-
Based on the Sensor model that you plan to use for this example, select the
Supported Device Types.
New Signature window 
-
Add the condition to the signature.
It is in the conditions that you specify the following details:
- The string that the Sensor should look for
- Which section of the HTTP request should it look for the string
- Proceed to add the condition.