Pattern matching within signatures is always implemented with string-match. String-match accepts a number of optional and required parameters. In the Text to Match text box, construct the string that contains the pattern to match. By default, pattern matches are case-sensitive. String-match accepts regular expressions in addition to simple strings.
Pattern match test parameters
Parameter | Description |
|---|---|
Protocol Field | The field that will be tested for a match with the supplied pattern |
Text to Match | Pattern to be matched |
Ignore Case | Select this option to make the expression case insensitive. By default it is case sensitive. |
Ignore String Position | Selecting this option enables you to create specific conditions. Offset: Use this to indicate where the Sensor should begin its search for the string. For example, if you set an offset of 5, then the Sensor checks for first byte of the string from the 5th byte of the payload. Depth: Use depth to indicate how far into the traffic should the Sensor look for the string. For example, if you set a depth of 10, the Sensor stops looking for the first byte of the string at the 10th byte from the beginning of the payload. Origin: Select Packet if you want the Sensor should apply the offset or depth to a packet. If you want the Sensor to apply the condition to the entire flow, select Flow. |