GL-1
User Guide for Cisco Security MARS Local Controller
78-17020-01
G L O S S A R Y
#
5-tuple
(Quintuple) The five pieces of data found within all IP-based network packets: source IP address,
source port, destination IP address, destination port, and protocol. You can define inspection rules,
queries, and reports using the data found in the 5-tuple.
A
(\
Access IP Address
This is the IP address that MARS uses to connect to the device and to get its configuration information.
MARS needs this address for NAT-related session correlation, attack path calculation, and mitigation
enter access information.
Activate
Making changes or edits known to the MARS after submitting changes.
D
Devices
The hosts and reporting devices present in the system.
Discovery
The act of identifying, either automatically or manually, devices in networks.
Dynamic
Vulnerability
Scanning
The MARS STM probes selected networks, and their components, for vulnerabilities.
E
Event
A security event reported to the MARS STM appliance. Events have: types, sources, destinations,
reporting devices, etc.
Event Types
Groups of similar security events. An event type is the normalized signature from a reporting device.
F
False Positive
An event that resembles a valid security threat, but is not.
Firing Events
An event that contributed to a rule firing.