139
Responding
Setting response parameters
Setting confidence levels
Symantec Network Security indicates the confidence level, a measure of the
likelihood of an actual attack. It determines the confidence level of the event by
analyzing the traffic behavior.
To set the confidence level
1
In the Network Security console, click
Configuration
>
Response Rules
.
2
Click the
Confidence
cell of the response policy table row.
3
Select one of the following symbols:
■
Less than (<)
■
Greater than (>)
■
Equal to (=)
4
Select one of the following confidence levels from the pull-down list:
■
Any
■
Very High
■
High
■
Medium
■
Low
■
Very Low
Setting event sources
The Network Security console can apply response rules to specific locations or
interfaces in the network using Event Source. The event source parameter
indicates that a rule applies only to events detected on a given interface. This
interface is not necessarily the target of the attack, but may in fact be the point
in the network at which Symantec Network Security is currently tracking the
attack. If the interfaces being inspected are receiving VLAN encapsulated
traffic, you can also specify that a rule applies to a specific VLAN ID.
To set the event source
1
In the Network Security console, click
Configuration
>
Response Rules
.
2
Click the
Event Source
cell of the response policy table row.
3
In
Select Event Source
, select the interfaces to which the response rule
applies.
4
Set VLAN if applicable, and click
OK
.
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...