171
Detecting
Configuring sensor detection
Streak Interval
Streak Interval
regulates how often the sensor checks traffic for port scans. In
past versions, Streak Interval and Counter Interval were controlled by the same
parameter. Symantec Network Security now provides two parameters that you
can configure independently.
The default is set to 16,383 for optimum sensitivity and performance, and does
not need to be changed under most circumstances. Valid values range from
1,023 to 16,383, inclusive. You can increase sensitivity to port scans by lowering
the value so that the sensor checks more often. Do not make changes to this
parameter without a thorough understanding of how it interacts with
TCP
Minimum Flows
,
UDP Minimum Flows
,
TCP Number of Streak Packets
, and
UDP
Number of Streak Packets
.
Note:
In versions prior to 4.0,
Streak Interval
and
Counter Interval
were
controlled by the same parameter. Symantec Network Security now provides
two parameters that you can configure independently.
TCP Minimum Flows
TCP Minimum Flows
regulates the number of unacknowledged TCP flows that
the sensor sends to analysis during the time period set by
Streak Interval
. If it
detects an alarming number of them, it sends the packets to streak analysis,
which inspects the sample of packets and compares IP addresses, ports, and
other characteristics for similarities.
The default is set to 3 for optimum sensitivity and performance, and does not
need to be changed under most circumstances. Valid values range from 3 to
twice the value of the
TCP Number of Streak Packets
parameter. Increasing the
value will decrease sensitivity. This parameter should not be changed without a
thorough understanding of how it interacts with
Streak Interval
and
TCP
Number of Streak Packets
.
UDP Minimum Flows
UDP Minimum Flows
regulates the number of unacknowledged UDP flows that
the sensor sends to analysis during the time period set by
Streak Interval
. If it
detects an alarming number of them, it sends the packets to streak analysis,
which inspects the sample of packets and compares IP addresses, ports, and
other characteristics for similarities.
The default is set to 3 for optimum sensitivity and performance, and does not
need to be changed under most circumstances. Valid values range from 3 to
twice the value of the
UDP Number of Streak Packets
parameter.
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...