Cisco IPS


Does anyone know if the AIP-SSM module for an ASA can protect against advanced web attacks like an application firewall?

Example, suppose I have a Microsoft ISA server behind the firewall on the DMZ doing reverse proxy for my web applications. The ISA does not have any addons that can protect against advanced web attacks such as cross-site-scripting, buffer overflow, sql injection, etc.
HOwever, if I stick an AIP-SSM module into the firewall would I be able to provide application layer protection at the module before traffic hits my ISA?
asavener, then would it be correct to say that an ASA with an AIM SSM module is also an application layer firewall?
thanks. just want to get another confirmation before I close and award the points.
Because if this is true, technically i won't need to invest in a software application firewall on my ISA server that is on the DMZ.