D-29
User Guide for Cisco Security MARS Local Controller
78-17020-01
Appendix D System Rules and Reports
List of System Reports
This report lists hosts that exhibit anomalous behavior by suddenly receiving statistically significant
volume on a TCP/UDP port or ICMP traffic.
•
Activity: Sudden Traffic Increase To Port - All Sources.
This report lists hosts that exhibit anomalous behavior by suddenly sending statistically significant
volume on a TCP/UDP port or ICMP traffic.
•
Activity: Sudden Traffic Increase To Port - All Sources.
This report lists hosts that exhibit anomalous behavior by suddenly sending statistically significant
volume on a TCP/UDP port or ICMP traffic.
•
Activity: Uncommon or Anomalous Traffic - All Events.
This report details uncommon or anomalous traffic such as unused TCP options, uncommon ICMP
traffic, non-standard traffic on standard port, tunneled traffic etc.
•
Activity: Uncommon or Anomalous Traffic - All Events.
This report details uncommon or anomalous traffic such as unused TCP options, uncommon ICMP
traffic, non-standard traffic on standard port, tunneled traffic etc.
•
Activity: Unknown Events - All Events.
This report tracks the events that are unknown to MARS.
•
Activity: Unknown Events - All Events.
Activity: Unknown Events - All Events
•
Activity: Virus/Worms - Top Event Types.
This report ranks the events that detect virus or worm activity in the network.
•
Activity: Virus/Worms - Top Event Types.
Activity: Virus/Worms - Top Event Types
•
Activity: Virus/Worms - Top Infected Hosts.
This report ranks hosts that are propagating virus and worms via SMTP, POP, IMAP, network shares
etc.
•
Activity: Virus/Worms - Top Infected Hosts.
Activity: Virus/Worms - Top Infected Hosts
•
Activity: Virus: Detected - Top Users.
This report ranks users/workstations by viruses detected.
•
Activity: Virus: Detected - Top Users.
Activity: Virus: Detected - Top Users
•
Activity: Virus: Infections - Top Users.
This report ranks users/workstations by viruses detected and not cleaned.
•
Activity: Virus: Infections - Top Users.
Activity: Virus: Infections - Top Users
•
Activity: Vulnerable Host Found via VA Scanner.
This report lists vulnerable hosts and associated vulnerabilities found by importing information
from Vulnerability Analysis (VA) scanners.
•
Activity: Vulnerable Host Found via VA Scanner.