D-Link DFL-2400 [75/112] The content tab

D-Link DFL-2400 [75/112] The content tab
DFL-2100/DFL-2400 Intrusion Detection System User Manual
6
5
The Content Tab
The Content tab consists parameters for searching payload of packets.
1. Match String: the string can be ASCII or HEX strings. If HEX string is used,
allowable alphabet is ‘0’-‘9’, ‘A’-‘F’, ‘a’-‘f’.
2. Matching offset: the offset from the start point of payload.
3. Matching method: the matching method can be,
z Case sensitive: lower case and upper case characters are different. This is
the default value.
z Case insensitive: ignore the differences of upper case and lower case
characters.
z Ignore white space: ignore the white space occurred in the payload, such
as blank, tab, new line, linefeed, carriage return.
z URL strings: the URL portion of payload will be extracted and parsed. And
the sub string of pattern before the character ‘?’ will be regarded as the base
part of URL, and the others are the parameters of URL. The URL matching is
case insensitive by default, but it won’t remove the white spaces.
Note If “Protocol Type” is IP, the matching starting point is
at the end of IP (layer 3) header, otherwise, it
would start matching from the end of layer 4
headers.
Note The order of URL parameters doesn’t matter. For
example, given a pattern “/cgi-
bin/foo.exe?p1=abc&p2=def”. An URL packet with
URL request “/cgi-bin/foo.exe?p2=def&p1=abc” is
considered as a match.

Содержание

Скачать