IPS signatures have three attributes: type (atomic or composite), trigger, and action (e.g., alert, log, deny, reset connection, or block traffic). Detection methods include pattern, anomaly, policy, or honeypot-based. Results can be true/false positives or negatives.Cisco Snort IPS