
WANGUARD 5.2 User Manual & Administrator's Guide
Response Configuration
Responses provide a unique and powerful way to automate reactons to trafc anomalies and atack
paterns. To add a Response, go to Confguraton » Network & Policy » Add Response. If you don't plan to use this
feature, you may safely skip this chapter.
When invoked by a Sensor or Filter, a Response runs the contained
Actons
. These are modules that provide
means to execute various commands, send notfcatons, write logs and more. There are 2 types of Actons:
●
Anomaly Actons
Are executed by Sensor, for each trafc anomaly while the anomaly is actve and once when it expires.
●
Patern Actons
Are executed by WANGUARD Filter, for each atack patern while the patern is actve and once when it
expires. Atack paterns are malicious packets that share common layer 3-7 felds (atacker IPs, TCP /
UDP ports, length, protocols, TTL, contents etc.).
To modify, delete or rename an Acton you must select the Acton's descripton in the lef secton. The <<List
Prefxes>> buton allows you to see what IP classes are confgured to use the Response.
All Actons have their specifc felds together with the following common felds:
●
Actve
selects if the Acton is enabled or disabled.
●
Priority
selects the order of executon relatve to the other Actons that are defned within the same
panel. Lower numerical values correspond to increased priority.
●
Descripton
is the name or descripton of the Acton.
●
Executon
. The Actons in the "While... is detected" panel can be executed every 5 seconds, depending
on the Sensor's Accuracy parameter. The name of the Acton is visible in the Console if
Log Executon
is
checked.
●
Conditons
are rules that must be passed before the Acton is executed. Each Conditon is formed from
a
Conditonal Parameter
, a comparison functon and a user-defned value. Conditonal Parameters are
dynamic, internal parameters that are updated every 5 seconds by Sensors and Filters.
Dynamic Parameters
are parameters defned within curly brackets - { and } that can be included in the body
of most Actons. Every Conditonal Parameter has a correspondence with a Dynamic Parameter.
Using the Custom Script Acton together with Dynamic Parameters you can extend and customize the
reacton to anomalies and paterns.
- 34 -
Содержание Wanguard 5.2
Страница 1: ......