After you create the attack definition, you create the signature for the attack.
Steps:
Click Signature-<signature name> tab.
(Optional) Clear the Name and type a new name for your signature.
For this example, you can leave the Benign Trigger Probability (BTP) and Target Host Architecture with the default values.
This example is to search for a string in the HTTP URI. So, select Request Packets as the Detection Window.
Based on the Sensor model that you plan to use for this example, select the Supported Device Types.
New Signature window.png)
Add the condition to the signature.
It is in the conditions that you specify the following details:
The string that the Sensor should look for
Which section of the HTTP request should it look for the string
Proceed to add the condition.