Chapter
6
Response Rules
This chapter includes the following topics:
■
About response rules
■
About automated responses
■
Viewing response rules
■
About response parameters
■
About response actions
■
About flow alert rules
About response rules
In addition to the ability to start detection and response immediately using
protection policies, Symantec Network Security also provides an automated,
rule-based response system. The response module responds to incidents
immediately, even if you cannot maintain system analysts on site around the
clock. The response module identifies, prioritizes, and responds appropriately to
whole classes of attacks, without requiring a separate response rule for each of
hundreds of individual base events. SuperUsers and Administrators can create
separate response rules specific to an individual event type, to any subset of
specified event types, or to all event types. This affords fast, effective responses
to suspicious behavior, and enables you to move quickly to stop attacks, even
DoS attacks, to mitigate potential damage, lost revenue, and the costs of
recovery.
The Symantec Network Security software and the Symantec Network Security
7100 Series appliance employ a common core architecture that provides
detection, analysis, storage, and response functionality. Most procedures in this
section apply to both the 7100 Series appliance and the Symantec Network
Security 4.0 software. The 7100 Series appliance also provides additional
Summary of Contents for 10268947 - Network Security 7160
Page 1: ...Symantec Network Security User Guide...
Page 18: ...18 Introduction Finding information...
Page 34: ...34 Architecture About management and detection architecture...
Page 46: ...46 Getting Started About deploying node clusters...
Page 64: ...64 Topology Database Viewing objects in the topology tree...
Page 124: ...124 Log Files About log files...
Page 134: ...134 Index...