The following is a list of the information you should have in hand as you create your custom attacks and the constituent signatures or rule. A signature or rule can range from very simple (for example, checking the value of a header field) to highly complex checks of different information in a specific order. You must have good bit of data to aid yourself in creating an accurate attack definition, such as the following:
Reason for creating this custom attack
Technical information references for this custom attack
Protocol in which this custom attack will search the traffic (also known as the impact protocol)
Specific hardware or software platforms affected by this traffic (also known as impact packages)
Severity of this event
The direction in which the "traffic to be watched for" occurs
Specific criteria that comprise the attack, such as field values and patterns to match
A method, data, or tool to be used for testing the attack before you use it in your production environment