The following is a list of the information you should have in hand as you create your custom attacks and the constituent signatures or rule. A signature or rule can range from very simple (for example, checking the value of a header field) to highly complex checks of different information in a specific order. You must have good bit of data to aid yourself in creating an accurate attack definition, such as the following:
- Reason for creating this custom attack
- Technical information references for this custom attack
- Protocol in which this custom attack will search the traffic (also known as the impact protocol)
- Specific hardware or software platforms affected by this traffic (also known as impact packages)
- Severity of this event
- The direction in which the "traffic to be watched for" occurs
- Specific criteria that comprise the attack, such as field values and patterns to match
- A method, data, or tool to be used for testing the attack before you use it in your production environment