WANGUARD 5.2 User Manual & Administrator's Guide
Anomalies Configuration
An important inital step in confguring WANGUARD is setng up anomalies detecton parameters and
decoders.
Anomalies detecton parameters are located in Confguraton » Global Setngs » Anomalies. The Sensors are
able to detect many types of trafc anomalies.
There are 2 categories / classes of trafc anomalies:
●
Threshold Anomalies
Are detected when a previously user-defned packets/s or bits/s rate threshold (absolute value or
percentage) has been reached. The trafc can be diferentated through decoders. Enable only the
decoders for the trafc for which you will apply thresholds. Decoders determine the underlying
protocols of each packet or fow.
●
Profle Anomalies
Are detected through a behavioral recogniton approach. The Sensors detect any actvity that deviates
from the "normal" trafc received by the protected subnets.
Afer enabling Profle Anomalies detecton for a subnet, the Sensor builds a behavioral trafc graph for
about 25 hours. Note that Profle Anomalies detecton is suited for hosts and subnets that have a
predictable trafc patern. Larger subnets are usually the more predictable.
False positves can be limited by adjustng the deviaton percent and minimum packets and bits rates.
Trafc anomalies detecton will be enabled individually for each subnet when confguring IP Zones on page
40.
- 33 -
Summary of Contents for Wanguard 5.2
Page 1: ......