
162
Sentinel 6.1 User Guide
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
8.2.2 Generating the Exploit Detection File
When you run the intrusion detection system or vulnerability type Collectors, events from all the
selected products are scanned for possible attacks and vulnerabilities, and the product name and
MSSP customer name are mapped to the Advisor product name and MSSP customer name. If the
events match successfully, the exploit information (IP address, Device Name, Attack Name, and
MSSP Customer Name) is updated in the
exploitdetection.csv
file in the
ESEC_HOME/data/
map_data
directory.
The initial mapping time might take up to 30 minutes. However, you can modify the time by
changing the value of the
minregenerateinterval
property in the
ExploitDetectDataGenerator
component of the
das_query.xml
file. The time is given in
milliseconds. For example, you can change the time from 1800000 (30 minutes) to 180000 (3
minutes).
NOTE:
You must restart the das_query services after you change the time.
8.2.3 Viewing the Events
To view events that indicate a possible exploitation, create an Active View with a filter that has the
Vulnerability value set to 1.
Within an event, the values in the Vulnerability field convey the following:
1:
the asset or destination device is possibly exploited.
0:
the asset or destination device is not exploited.
NOTE:
If the Vulnerability field is blank, the exploitdetection.csv file is not generated.
For more information on viewing events in Active Views, see
Section 2.4, “Viewing Real Time
Events,” on page 39
.
8.3 Introduction to the Advisor User Interface
Section 8.3.1, “The Advisor Window,” on page 163
Section 8.3.2, “Processing the Advisor Feed,” on page 164
Section 8.3.3, “Configuring the Advisor Products for Exploit Detection,” on page 165
Ensure that you have Advisor Configuration permission to access the Advisor window.
You can access the Advisor user interface through one of the following methods:
Summary of Contents for SENTINEL 6.1 SP2
Page 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Page 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Page 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Page 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...