D-13
User Guide for Cisco Security MARS Local Controller
78-17020-01
Appendix D System Rules and Reports
List of System Reports
This rule detects Modbus servers restarting. Modbus protocol is the defacto standard in industrial
control communications and is the protocol of choice in a Supervisory Control and Data Acquisition
(SCADA) communications network, where the Programmable logic controllers (PLCs) act as
Modbus servers.
•
System Rule: Sudden Traffic Increase To Port.
This rule detects scans statistically significant increase in traffic to a particular port.
•
System Rule: Virus Found - Cleaned.
This rule indicates that virus scanning software detected and was able to clean a virus.
•
System Rule: Virus Found - Not Cleaned.
This rule indicates that virus scanning software detected but was unable to clean a virus.
•
System Rule: Vulnerable Host Found.
This rule detects a vulnerable host in the network - such hosts typically run old vulnerable protocols
(e.g. SSH version 1, Rexec) or authenticate using plaintext passwords.
•
System Rule: Worm Propagation - Attempt.
This correlation rule detects worm propagation via means such as SMTP, TFTP, and network shares.
•
System Rule: Worm Propagation - Success Likely.
This correlation rule detects worm propagation via means such as SMTP, TFTP, and network shares
accompanied by suspicious follow-up activity at the target destination host. Suspicious follow-up
activity may include the host scanning the network, creating excessive firewall deny traffic, a
backdoor opening up at the server etc.
List of System Reports
This topic defines the complete list of system reports issued with this release.
•
[MARS Internal: Netflow: Top Destination Ports].
This report ranks the destination ports in events seen by MARS. This is for internal use only.
•
[MARS Internal: Netflow: Top Destination Ports].
[MARS Internal: Netflow: Top Destination Ports]
•
[MARS Internal: Netflow: Top Hosts/Destination Ports Byte Count].
This report ranks the destination ports in events seen by MARS. This is for internal use only.
•
[MARS Internal: Netflow: Top Hosts/Destination Ports Byte Count].
[MARS Internal: Netflow: Top Hosts/Destination Ports Byte Count]
•
[MARS Internal: Netflow: Top Hosts/Destination Ports Flow Count].
This report ranks the destination ports in events seen by MARS. This is for internal use only.
•
[MARS Internal: Netflow: Top Hosts/Destination Ports Flow Count].
[MARS Internal: Netflow: Top Hosts/Destination Ports Flow Count]
•
Activity: AAA Based Access - All Events.
This report details AAA based access (e.g. to the network or to specific devices).
•
Activity: AAA Based Access - All Events.
Activity: AAA Based Access - All Events