
Sentinel Architecture
445
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
Streaming Maps
Map Service employs a dynamic update model and streams the maps from one point to another,
avoiding the build up of large static maps in dynamic memory. The value of this streaming
capability is particularly relevant in a mission-critical real-time system such as Sentinel where there
needs to be a steady, predictive and agile movement of data independent of any transient load on the
system.
Exploit Detection (Mapping Service)
Sentinel provides the ability to cross-reference event data signatures with Vulnerability Scanner
data. Users are notified automatically and immediately when an attack is attempting to exploit a
vulnerable system. This is accomplished through:
Advisor Feed
Intrusion detection
Vulnerability scanning
Firewalls
Advisor provides a cross-reference between event data signatures and vulnerability scanner data.
Advisor feed has an alert and attack feed. The alert feed contains information about vulnerabilities
and threats. The attack feed is a normalization of event signatures and vulnerability plug-ins. For
more information on Advisor, see
Chapter 8, “Advisor Usage and Maintenance,” on page 159
.
You require at least one vulnerability scanner and either an IDS, IPS, or firewall. The IDS and
Firewall DeviceName should appear in the RV31 field of the event. Also, the IDS and Firewall must
properly populate the DeviceAttackName (rt1) field (for example, WEB-PHP Mambo
uploadimage.php access).
The Advisor feed is sent to the database and then to the Exploit Detection Service. The Exploit
Detection Service generates one or two files depending on the kind of data that has been updated.
Figure A-3
Exploit Detection
The Exploit Detection Map Files are used by the Mapping Service to map attacks to exploits of
vulnerabilities.
Summary of Contents for SENTINEL 6.1 SP2
Page 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Page 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Page 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Page 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Page 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...