Glossary
GL-3
User Guide for Cisco Security MARS Local Controller
78-17020-01
Reporting IP
Address
This is the IP address as it appears to MARS. This address is where the logs (syslog, SNMP traps, LEA)
come from.
Rule
The sub-set of events that contributed to the incidents of the specified rules firing.
S
Service
A protocol and range of IP addresses.
Session
A session is a collection of events that all share a common source and destination, which were reported
within a given time window. For example, usually the events in a session map well to the events
generated between the opening and closing of a TCP/IP connection.
Sessionize
Combining event data from multiple reporting devices to reconstruct the occurrence of a session.
Sessionizing takes two forms: reconstructing a session-oriented protocol, such as TCP, where the initial
handshake and the session tear down and reconstructing a sessionless protocol, such as UDP, where the
initial start and session end times are defined more based on first and last packets tracked within a
restricted time period. In other words, packets that fall outside of the time period are considered part
of different sessions.
T
True Positive
A valid security threat.
U
Unreported device
A device from which the MARS Appliance receives events, such as syslog messages, SNMP
notifications, or NetFlow events, but the device is not defined in the appliance. Without a definition,
MARS is unable to correlate events correctly as it needs to know which message format to use in
parsing.
T
True Positive
A valid security threat.