17-8
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 17 Network Summary
Summary Page
Recent Incidents
The first feature to notice about the Dashboard are the recent incidents that have fired. The
Local Controller comes with pre-defined rules, and these incidents are the result of those rules firing.
These rules are generic, globally applicable, and should serve you well as a starting point once you begin
to tune the Local Controller.
Figure 17-14
Drilling-down into Incidents
Sessions and Events
Within a given time window, a session is a collection of events that all share a common end-to-end:
•
Source and destination address
•
Source and destination port
•
Protocol
Event sessionization aggregates event data making it easier to sort and examine. Event sessionization
lets the system treat events as single units of information and helps you understand if an attack truly has
materialized. It gives you the context of the attack by giving you all the events on that session.
Sessionization works across NAT (network address translation) boundaries – if a session traverses a
device that does NAT on that session, the Local Controller is able to sessionize events even if they are
reported by two devices on either side of that firewall.
Networks start to show immediate action in the events and sessions categories. Note that the 24 Hour
Events table and the Events and Sessions chart are different ways of presenting the same information.
1
Link to the Incident sessions detail page
5
Link to the rule details page
2
Incident severity icons
6
Incident Path icon
launches the topology
diagram popup window
3
Link to the Event Type Details page
7
Incident Vector icon
launches the incident
attack vector diagram
4
Query icon links to Query page
8
Link to the View Case page
143153
2
3
4
1
5
6
7
8
Red—Severe threat
Yellow—Possible threat
Green—Unlikely threat
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...