<?xml version="1.0"?>
<!--
#*************************************************************
#
#  Copyright (c) 2003-2007, Bleeding Edge Threats
#  All rights reserved.
#
#  Redistribution and use in source and binary forms, with or without modification, are permitted provided that the
#  following conditions are met:
#
#  * Redistributions of source code must retain the above copyright notice, this list of conditions and the following
#    disclaimer.
#  * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the
#    following disclaimer in the documentation and/or other materials provided with the distribution.
#  * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived
#    from this software without specific prior written permission.
#
#  THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES,
#  INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
#  DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
#  SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
#  SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
#  WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
#  USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
#
#
# For more information see http://www.bleedingthreats.net
# All convertable rules from Bleeding Sbort are available in this format.
#
#
-->
<NetworkSensorConfiguration daemonize="yes" debug="no" threaded="yes">
   <Device pcap="no" time-out-msec="500" name="DRAGON-DEFAULT">
      <Interface name="eth0"/>
   </Device>
   <SearchEngines search-groups="1" threads-per-group="1" mq-size="1024" buffer-mq="yes" pre-capture-buffer-size="0" pre-capture-all-events="no" adaptive="yes" disable="no"/>
   <PerformanceReport seconds="0" packets="0" sniffer-only="no" no-search="no" 
                packet-length="no" ports-stats="no"/>
   <Heartbeat rate="60" rollover="0"/>
   <SensorConfig name="DRAGON-DEFAULT" default="no">
      <Configuration>
         <ProtectedNetwork internal-same-as-from="no">
            <Network ip="0.0.0.0" mask="24"/>
         </ProtectedNetwork>
         <Logging ring-buffer="yes" alarmlog-file="no" alarmlog-display="no" 
                  local-db="no" swatch="no">
         </Logging>
		 <SNMPTrap disable="yes" object-id="1.3.6.1.4.1.4471"/>
         <ProbeDetection disable="no" verbose="yes" debug="no"
                         protocol-scan="3" protocol-ping="10" 
                         ports-per-host="5" hosts-per-port="5"
                         distributed-ports-per-host="5" distributed-hosts-per-port="5"
                         max-threshold="50000">
            <PortRange low="0" high="1023" direction="toward"/>
            <PortRange low="1032" high="1032" direction="toward"/>
            <PortRange low="1257" high="1257" direction="toward"/>
            <PortRange low="1520" high="1530" direction="toward"/>
            <PortRange low="2049" high="2049" direction="toward"/>
            <PortRange low="2301" high="2301" direction="toward"/>
            <PortRange low="2745" high="2745" direction="toward"/>
            <PortRange low="3127" high="3127" direction="toward"/>
            <PortRange low="3306" high="3306" direction="toward"/>
            <PortRange low="6000" high="6010" direction="toward"/>
            <PortRange low="6112" high="6112" direction="toward"/>
            <PortRange low="6129" high="6129" direction="toward"/>
            <PortRange low="8999" high="8999" direction="toward"/>
            <PortRange low="20168" high="20168" direction="toward"/>
            <PortRange low="32700" high="33430" direction="toward"/>
            <PortRange low="65506" high="65506" direction="toward"/>
         </ProbeDetection>
         <ActiveResponse disable="yes" interface="eth0" tcp-ecm="no"/>
         <Dynamic cushion="0" logging="yes"/>
         <NetworkLayer log-localhost-traffic="yes" same-address="yes" null-address="yes"
                       favor-old="yes" resv-bit="yes" tcp-frag-first-packet="yes"
                       tcp-frag-flags-overlay="yes" frag-small="32"
                       frag-large="yes" options-check="yes" drop-ttl="2" log-ttl="0"
                       max-mtu="1500" max-mtu-verbose="yes" frag-rebuild-hash="3301"
                       disable="no" verbose="no" debug="no" frag-rebuild="yes" frag-rebuild-size="low">
         </NetworkLayer>
         <TCPState max-sessions="50000" action="none" disable="no"/>
         <TransportLayer port-zero="no"
                         syn-data-max="10" syn-nonzero="yes" tcp-options-check="no"
                         syn-bomb-threshold="500" trust="no" disable="no" debug="no"
                         verbose="yes">
            <StreamRebuilding force-rebuild="yes" min-length="3" rebuild-to="yes" 
                              rebuild-from="yes" rebuild-all="yes" session-window="100"
                              disable="no" debug="no" verbose="no" session-window-size="high"
                              session-rebuild-size="high"/>
        <Flags flags="SF"/>
        <Flags flags="SR"/>
        <Flags flags="FSRPAU"/>
        <Flags flags="FSRPU"/>
        <Flags flags="N"/>
        <Flags flags="FUP"/>
        <Flags flags="FSR"/>
         </TransportLayer>
         <RPCAnalysis verbose="no" any-port="no" inbound-only="yes" disable="no" debug="no">
           <PortMacroName name="R"/>
         </RPCAnalysis>
         <TelnetAnalysis debug="no" verbose="no" disable="no" binary="yes" bad-cmd="yes">
           <Port port="23"/>
         </TelnetAnalysis>
         <FTPAnalysis verbose="no" debug="no" disable="no" port-request-check="yes">
            <Port port="21"/>
         </FTPAnalysis>
         <DNSAnalysis verbose="no" debug="no" disable="no">
            <Port port="53"/>
         </DNSAnalysis>
         <FingerAnalysis verbose="no" debug="no" disable="no">
            <Port port="79"/>
         </FingerAnalysis>
         <SNMPAnalysis verbose="no" debug="no" disable="no">
            <Port port="161"/>
         </SNMPAnalysis>
         <HTTPAnalysis verbose="no" unicode="yes" iis-unicode="yes" 
                      multi-method="yes" null-method="no" doc-root="no" fast-analyze="yes" debug="no" disable="no">
            <Port port="80" direction="toward"/>
            <Port port="8080" direction="toward"/>
            <Port port="3128" direction="toward"/>
         </HTTPAnalysis>
         <RIPAnalysis verbose="no" debug="no" disable="no"/>
         <H225Analysis verbose="no" debug="no" disable="no">
         <Port port="1720" />
         </H225Analysis>
         <SIPAnalysis verbose="no" debug="no" disable="no">
         <Port port="5060" />
         </SIPAnalysis>
         <SMBAnalysis log-netbios-session-failures="yes" log-remote-session-attempts="yes" 
                      log-admin-login-attempts="yes" log-null-login-attempts="yes"
                      debug="no" disable="no" verbose="no">
            <Port port="135"/>
            <Port port="445"/>
            <PortRange direction="any" low="137" high="139"/>
         </SMBAnalysis>
         <ICMPAnalysis large="1400" debug="no" disable="no" verbose="no">
         </ICMPAnalysis>
         <DoSCheck verbose="no" debug="no" disable="no"/>
         <CovertChannelAnalysis loki-check="yes" 
                                debug="no" disable="no" verbose="no"/>
        <PortMacro name="W">
                <Port direction="any" port="80" />
                <Port direction="any" port="8080" />
                <Port direction="any" port="3128" />
        </PortMacro>
        <PortMacro name="U">
                <Port direction="any" port="22" />
                <Port direction="any" port="53" />
                <Port direction="any" port="143" />
                <Port direction="any" port="443" />
                <Port direction="any" port="2049" />
        </PortMacro>
        <PortMacro name="N">
                <Port direction="any" port="23" />
                <Port direction="any" port="53" />
                <Port direction="any" port="80" />
                <Port direction="any" port="135" />
                <Port direction="any" port="139" />
        </PortMacro>
        <PortMacro name="X">
                <PortRange direction="any" low="6000" high="6070" />
        </PortMacro>
        <PortMacro name="H">
                <PortRange direction="any" low="1024" high="65535" />
        </PortMacro>
        <PortMacro name="L">
                <PortRange direction="any" low="0" high="1023" />
        </PortMacro>
        <PortMacro name="A">
                <PortRange direction="any" low="0" high="65535" />
        </PortMacro>
        <PortMacro name="M">
                <Port direction="any" port="161" />
                <Port direction="any" port="162" />
                <PortRange direction="any" low="32770" high="32800" />
        </PortMacro>
        <PortMacro name="S">
                <NotPort direction="any" port="22" />
        </PortMacro>
        <PortMacro name="B">
                <NotPort direction="any" port="80" />
        </PortMacro>
        <PortMacro name="P">
                <Port direction="any" port="21" />
                <Port direction="any" port="80" />
                <Port direction="any" port="119" />
        </PortMacro>
        <PortMacro name="Q">
                <PortRange direction="any" low="27900" high="27999" />
        </PortMacro>
        <PortMacro name="T">
                <Port direction="any" port="21" />
                <Port direction="any" port="23" />
        </PortMacro>
        <PortMacro name="R">
                <Port direction="any" port="111" />
                <PortRange direction="any" low="32768" high="32900" />
        </PortMacro>
      </Configuration>
      <NetworkSignatures>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003475">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20abc/2fabc"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ ABC Torrent User-Agent (ABC/ABC-3.1.0)]]></Description>
        <Reference name="URLREF"><![CDATA[http://pingpong-abc.sourceforge.net]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001059">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20Ares"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Ares traffic]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.aresgalaxy.org]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="5190" match-neg-port="yes" follow-on-sig="no" name="DC:2001756">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/50/55/53/48/20/53/48/41/31/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Ares File Upload]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.aresgalaxy.org]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2003437">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Match match-order="0" offset="36" depth="7">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Ares/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Ares over UDP]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006371">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20BearShare/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE BearShare P2P Gnutella Client User-Agent (BearShare 6.x.x.x)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006379">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fgnutella/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fclient/3dbear"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/26version/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE BearShare P2P Gnutella Client HTTP Request]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2000334">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="6">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/0d/06/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P BitTorrent peer sync]]></Description>
        <Reference name="URLREF"><![CDATA[http://bitconjurer.org/BitTorrent/protocol.html]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2000357">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/40/09/07/00/00/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P BitTorrent Traffic]]></Description>
        <Reference name="URLREF"><![CDATA[http://bitconjurer.org/BitTorrent/protocol.html]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="6969" match-neg-port="no" follow-on-sig="no" name="DC:2000369">
        <ExtendedLanguage src-port="any" dst-port="6969">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/2fannounce"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P BitTorrent Announce]]></Description>
        <Reference name="URLREF"><![CDATA[http://bitconjurer.org/BitTorrent/protocol.html]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006372">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20Bittorrent/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bittorrent P2P Client User-Agent (Bittorrent/5.x.x)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006375">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ftrackerphp/2fannounce/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fport/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/26peer/5fid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bittorrent P2P Client HTTP Request]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="41170" match-neg-port="no" follow-on-sig="no" name="DC:2003172">
        <ExtendedLanguage src-port="any" dst-port="41170">
        <Match match-order="0" depth="3" distance="16">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/01/02/00"/>
        </Match>
        <Match match-order="1" depth="2" distance="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="FN"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Manolito Search Query]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.blubster.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002814">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="source-client" state="established"/>
        <Match match-order="0" offset="0" depth="7">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/24MyINFO"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Direct Connect Traffic (client-server)]]></Description>
        <Reference name="URLREF"><![CDATA[http://en.wikipedia.org/wiki/Direct_connect_file-sharing_application]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="4660" match-neg-port="no" follow-on-sig="no" name="DC:2000332">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3"/>
        </Match>
        <Match match-order="1" offset="2" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/47"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P ed2k request part]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/practical/GCIH/Ian_Gosling_GCIH.pdf]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="4660" match-neg-port="no" follow-on-sig="no" name="DC:2000333">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3"/>
        </Match>
        <Match match-order="1" offset="2" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/59"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P ed2k file request answer]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/practical/GCIH/Ian_Gosling_GCIH.pdf]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2000340">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Match match-order="0" offset="0" depth="6">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/0c/b0"/>
        </Match>
        <AlertLimit num-alerts="1" interval="600" hard-limit="yes" threshold-limit="yes" apply-to="dst"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Kaaza Media desktop p2pnetworking.exe Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/practical/GCIH/Ian_Gosling_GCIH.pdf]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="4660" match-neg-port="no" follow-on-sig="no" name="DC:2001296">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/14"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P eDonkey File Status]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.edonkey.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="4660" match-neg-port="no" follow-on-sig="no" name="DC:2001297">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/11"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P eDonkey File Status Request]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.edonkey.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="4660" match-neg-port="no" follow-on-sig="no" name="DC:2001298">
        <ExtendedLanguage>
        <Match match-order="0" offset="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/96"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P eDonkey Server Status Request]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.edonkey.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="source" traffic-direction="from" dynamic-collection="0" port="4660" match-neg-port="no" follow-on-sig="no" name="DC:2001299">
        <ExtendedLanguage>
        <Match match-order="0" offset="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/97"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P eDonkey Server Status]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.edonkey.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003308">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/1b"/>
        </Match>
        <PayloadSize min="4" max="4" match-zero="no"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[BEedk.ip.requestect]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey IP Request]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003309">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/1c"/>
        </Match>
        <PayloadSize min="0" max="20" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BEedk.ip.requestect]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey IP Reply]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003316">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/1d"/>
        </Match>
        <PayloadSize min="0" max="20" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey IP Query End]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003310">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/0c"/>
        </Match>
        <PayloadSize min="15" max="1514" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey Publicize File]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003311">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/0d"/>
        </Match>
        <PayloadSize min="0" max="20" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey Publicize File ACK]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003312">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/0a"/>
        </Match>
        <PayloadSize min="25" max="25" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey Connect Request]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003313">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/0b"/>
        </Match>
        <PayloadSize min="200" max="1514" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey Connect Reply and Server List]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003314">
        <ExtendedLanguage>
        <Match match-order="0" depth="3">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/0e/14"/>
        </Match>
        <PayloadSize min="19" max="19" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey Search Request (by file hash)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003315">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/0f"/>
        </Match>
        <PayloadSize min="200" max="1514" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey Search Reply]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003317">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/0e"/>
        </Match>
        <PayloadSize min="19" max="1514" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey Search Request (any type file)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003318">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/9a"/>
        </Match>
        <PayloadSize min="19" max="19" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey Get Sources Request (by hash)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003319">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/98"/>
        </Match>
        <Match match-order="1" within="3">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/01"/>
        </Match>
        <PayloadSize min="5" max="1514" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey Search Request (search by name)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003320">
        <ExtendedLanguage>
        <Match match-order="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/e3/99"/>
        </Match>
        <PayloadSize min="21" max="1514" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Edonkey Search Results]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.giac.org/certified_professionals/practicals/gcih/0446.php]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="443" match-neg-port="no" follow-on-sig="no" name="DC:2002673">
        <ExtendedLanguage src-port="443" dst-port="any">
        <Flow direction="target-client" state="established"/>
        <Match match-order="0" offset="392" depth="18">
        <ExtendedPattern uri-decode="no" type="string" pattern="/0bfoldershare/30/81/9f/30"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P MS Foldershare Login Detected]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.foldershare.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001664">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="17">
        <ExtendedPattern uri-decode="no" type="string" pattern="gnutella/20connect/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Gnutella Connect]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.gnutella.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002760">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="SCP/40/83DNA/40"/>
        </Match>
        <AlertLimit num-alerts="10" interval="600" hard-limit="yes" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P GnucDNA UDP Ultrapeer Traffic]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2002761">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="gnutella"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="x/2dultrapeer/3a/20true"/>
        </Match>
        <AlertLimit num-alerts="5" interval="3600" hard-limit="yes" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Gnutella TCP Ultrapeer Traffic]]></Description>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="6667" match-neg-port="no" follow-on-sig="no" name="DC:2000338">
        <ExtendedLanguage src-port="6667" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" depth="500">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/54/6f/20/72/65/71/75/65/73/74/20/61/20/66/69/6c/65/20/74/79/70/65/3a/20/22/2f/6d/73/67"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P iroffer IRC Bot help message]]></Description>
        <Reference name="URLREF"><![CDATA[http://iroffer.org]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="6667" match-neg-port="no" follow-on-sig="no" name="DC:2000339">
        <ExtendedLanguage src-port="6667" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" depth="500">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/54/6f/74/61/6c/20/4f/66/66/65/72/65/64/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P iroffer IRC Bot offered files advertisement]]></Description>
        <Reference name="URLREF"><![CDATA[http://iroffer.org]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2001796">
        <ExtendedLanguage>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="kazaa"/>
        </Match>
        <AlertLimit num-alerts="10" interval="60" hard-limit="no" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P kazaa over UDP]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.kazaa.com/us/index.htm]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001812">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="agent/3a/20kazaaclient"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ KazaaClient P2P Traffic]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.kazaa.com/us/index.htm]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001808">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20limewire"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P LimeWire P2P Traffic]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.limewire.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2001809">
        <ExtendedLanguage>
        <Match match-order="0" offset="25" depth="10">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/49/50/40/83/53/43/50/41/00/00"/>
        </Match>
        <PayloadSize min="35" max="35" match-zero="no"/>
        <AlertLimit num-alerts="1" interval="360" hard-limit="yes" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Limewire P2P UDP Traffic]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.limewire.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="6345" match-neg-port="no" follow-on-sig="no" name="DC:2001841">
        <ExtendedLanguage>
        <AlertLimit num-alerts="40" interval="300" hard-limit="no" threshold-limit="yes" apply-to="src"/>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P UDP traffic - Likely Limewire]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.limewire.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001035">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fmorpheus/2fmorpheus/2eexe"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Morpheus Install]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.morpheus.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001036">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fmorpheus/2fmorpheus/5fsm/2eini"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Morpheus Install ini Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.morpheus.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001037">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fgwebcache/2fgcache/2easg/3fhostfile/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Morpheus Update Request]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.morpheus.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="both" traffic-direction="any" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2000335">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Match match-order="0" offset="36">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/02/03/00/6c/6f/63"/>
        </Match>
        <Match match-order="1" distance="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/62/63/70/3a/2f/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Overnet (Edonkey) Server Announce]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.overnet.com]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="any" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2000015">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Wonk/2d"/>
        </Match>
        <Match match-order="1" within="15">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/23waste/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Phatbot Control Connection]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.lurhq.com/phatbot.html]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001188">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="slsknet"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Soulseek]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.slsknet.org]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="2234" match-neg-port="no" follow-on-sig="no" name="DC:2001187">
        <ExtendedLanguage src-port="2234" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/09/00/00/00/78"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MISUSE</EventGroup>
        <Description><![CDATA[ P2P Soulseek Filesearch Results]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.slsknet.org]]></Reference>
        <Score>Low</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
      </NetworkSignatures>
   </SensorConfig>
</NetworkSensorConfiguration>
