21-12
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 21 Rules
Constructing a Rule
Severity
The value of this condition can be
one of the following:
•
ANY
—(Default) Specifies that
this rule is applied to events of all
severity levels.
•
Green
—Restricts this rule to
firing against low-severity events.
•
Yellow
—Restricts this rule to
firing against medium-severity
events.
•
Red
—Restricts this rule to firing
against high-severity events.
Count
Identifies the number of items the
event must occur before the
condition is met. The value for this
condition is a whole number ranging
between 1 and 100. The default
value is 1.
Note
Events of the same event
type occurring in the same
session in a three-second
period increment the active
count by one. This inherent
threshold ensures that a
event floods of the same
type does not increase the
active count arbitrarily and
incorrectly fire the rule.
Example usage
: When a backdoor
rootkit install is detected, the count
should be 1 as it is only going to be
reported once and it is not something
you expect to ever see on your
network. However, if you are using
deny messages to detect infected
hosts, you may want the count value to
be higher. For example, you may want
to allow for several common mistakes,
such as password failures, before
firing a rule for the event. People
accidentally mistype passwords, they
don’t accidentally install a rootkit.
Close
Identifies the close of a clause.
Table 21-1
Rule Fields and Arguments
Rule Field
Field Description and Arguments
Argument Descriptions