19-6
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 19 Incident Investigation and Mitigation
False Positive Confirmation
The following information describes some of the fine points of this table.
•
Instances
Sometimes rows are split into instances. The
only
relationship among the different instances is that they
fired the same rule in the same time frame.
•
Session/Incident ID
This column shows the sessions that contributed to the incident, and the other incidents those sessions
belong to.
•
Events column
The Events column shows types of the firing events. Multiple firing events of the same types are shown
once per session.
•
Time column
An incident’s duration only includes the events that contributed to the incident firing.
False Positive Confirmation
When investigating incidents, you will invariably come across false positive events. In some cases, firing
events are classified automatically by MARS as system-confirmed false positives and unconfirmed false
positives. Vulnerability scanning often identifies the false positive events, but at times you must
investigate events to determine their validity.
To understand the false positive nomenclature and what tasks you are expected to perform within the
user interface, we must study the possibilities among three variables surrounding possible attacks:
legitimate attack, valid target, and attack detected. We examine these differences in
Table 19-1
.
Based on the valid cases in
Table 19-1
, we can clearly distinguish the false positive terminology:
7
Launchs False Positive popup window
8
Link to the Device Information page
9
Query icon links to Query page
10
Click Device icon to launch popup window to
display raw message information
11
Link to the Mitigation Information page
12
Link to the False Positive Tuning page
Table 19-1
Attack Type Truth Table
Legitimate Attack
Valid Target
Attack Detected
invalid scenario
0
0
0
False Positive
0
0
1
invalid scenario
0
1
0
False Positive
0
1
1
False Negative
1
0
0
Attack/Alarm (noise)
1
0
1
True False Negative
1
1
0
Intrusion/True Alarm
1
1
1
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...