19-8
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 19 Incident Investigation and Mitigation
False Positive Confirmation
have the option of dropping the event from incident evaluation and either shoring it in the database or
not. Whether you store the event in the database or not, events matching the event type and target host
can no longer act as firing events. By refining the event processing in this fashion, MARS frees up your
time to focus on actual incidents by more accurately correlating events into incidents and reducing noise.
As part of your operational strategy, you should strive to refine event generation and processing to tune
out the possibility for false positives. You can perform such tuning at the device level, by refining what
traffic or action can generate an event, and at the Local Controller level by providing more information
about your network, such as identifying the operating system of hosts attached to the network segments
monitored by that Local Controller.
The False Positive Page
To navigate to the False Positives page, click
Incidents
, and click the
False Positives
sub-tab.
The False Positives page is where you can see groupings of False Positives.
You can filter categories by clicking on the
Select False Positive
drop-down list. Your choices are:
•
Unconfirmed false positive type
For this type, the MARS needs user confirmation to determine if the target host is vulnerable to the event
type in question.
•
User confirmed false positive type
For this type, a user has provided confirmation that a firing event is a false positive.
•
User confirmed positive type
For this type, a user has provided confirmation that a firing event is a true attack.
•
System determined false positive type
For this type, the system has determined that a firing event is a false positive.
In the False Positives table, you can see how many sessions the false positive has appeared in, the event
type, the false positive status confirmation icons, the event type information icon, the destination IP and
its port, the destination IP information icon, its protocol, zone, and you can see the sessions that are
related to the false positive.
Figure 19-6
False Positive Table
1
Link to the Event Type Details page
2
Query icon links to the Query page and
automatically populates the corresponding
Query field
3
False Positive type and severity icon
4
Launches the Security Device Information
popup window
5
Launches Port Information popup window
6
Launches False Positive Sessions Details
popup window
143423
2
1
3
4
5
6
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...