The Default section displays applications which support TCP, UDP, and IP that are commonly used/allowed, but do not use a standardized protocol and may be used for malicious purposes. The Custom Attack Editor enables you to monitor usage of programs such as NetMeeting and PCAnywhere in order to prevent external attacks. For example, your security policy may allow the use of PCAnywhere to resolve desktop/server issues remotely, but the program can also be used to infiltrate your network and perform malicious acts. The Custom Attack Editor enables you to create a pattern-matching signature for responses or requests to/from any of the listed programs for monitoring purposes.
To create a signature for any of these instances, simply create a signature instance, and select Packet Grep Protocol Match as a comparison for a condition.
.png)