23-4
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 23 Preventing Network Attacks
Configuring Threat Detection
The
average-rate
av_rate
argument can be between 0 and 2147483647 in drops/sec.
The
burst-rate
burst_rate
argument can be between 0 and 2147483647 in drops/sec. The burst rate is
calculated as the average rate every
N
seconds, where
N
is the burst rate interval. The burst rate interval
is 1/60th of the average rate interval or 10 seconds, whichever is larger.
You can configure up to three different rate intervals for each event type.
The following example enables basic threat detection, and changes the triggers for DoS attacks:
hostname(config)#
threat-detection basic-threat
hostname(config)#
threat-detection rate dos-drop rate-interval 600 average-rate
60
burst-rate 100
Managing Basic Threat Statistics
•
To view basic threat statistics, enter the following command:
hostname#
show
threat-detection rate
[
min-display-rate
min_display_rate
] [
acl-drop
|
bad-packet-drop
|
conn-limit-drop
|
dos-drop
|
fw-drop
|
icmp-drop
|
inspect-drop
|
interface-drop
|
scanning-threat
|
syn-attack
]
where the
min-display-rate
min_display_rate
argument limits the display to statistics that exceed
the minimum display rate in events per second. You can set the
min_display_rate
between 0 and
2147483647.
For a description of each event type, see the
“Basic Threat Detection Overview” section on
page 23-2
.
The output shows the average rate in events/sec over two fixed time periods: the last 10 minutes and
the last 1 hour. It also shows: the current burst rate in events/sec over the last completed burst
interval, which is 1/60th of the average rate interval or 10 seconds, whichever is larger; the number
of times the rates were exceeded (triggered); and the total number of events over the time periods.
The security appliance stores the count at the end of each burst period, for a total of 60 completed
burst intervals. The unfinished burst interval presently occurring is not included in the average rate.
For example, if the average rate interval is 20 minutes, then the burst interval is 20 seconds. If the
last burst interval was from 3:00:00 to 3:00:20, and you use the
show
command at 3:00:25, then the
last 5 seconds are not included in the output.
The only exception to this rule is if the number of events in the unfinished burst interval already
exceeds the number of events in the oldest burst interval (#1 of 60) when calculating the total events.
In that case, the security appliance calculates the total events as the last 59 complete intervals, plus
the events so far in the unfinished burst interval. This exception lets you monitor a large increase in
events in real time.
•
To clear basic threat statistics, enter the following command:
hostname#
clear threat-detection rate
The following is sample output from the
show threat-detection rate
command:
hostname#
show threat-detection rate
Average(eps) Current(eps) Trigger Total events
10-min ACL drop: 0 0 0 16
1-hour ACL drop: 0 0 0 112
1-hour SYN attck: 5 0 2 21438
10-min Scanning: 0 0 29 193
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......