21-25
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 21 Rules
Rule and Report Groups
•
Add, Modify, and Delete a Rule Group, page 21-27
•
Add, Modify, and Delete a Report Group, page 21-30
•
Display Incidents Related to a Rule Group, page 21-32
•
Create Query Criteria with Report Groups, page 21-33
•
Using Rule Groups in Query Criteria, page 21-34
Rule and Report Group Overview
Note
To view a list of all System Inspection rules and reports, see
Appendix D, “System Rules and Reports.”
Rule and report groups help you manage rules and reports by speeding access to those rules and reports
relevant to your task at hand. You can create groups, or use the groups provided with CS-MARS (System
groups). Groups act as filters to limit the display of rules, reports, and incidents in the CS-MARS HTML
interface. All groups can be modified or deleted.
CS-MARS provides over 100 system rules and 150 system reports. More can be added by creating
custom rules and reports, and by performing periodic software updates. A rule or report group contains
a subset of these rules or reports as members. Usually rules or reports within the same group have related
functions (such as, reconnaissance activities, server attack, etc.). When you select a group from a
dropdown filter, only those rules and reports that are members are displayed on the page. When you
select a rule group on the Incidents page, only those incidents related to the rules of the selected group
display. Report and rule groups can also be used when constructing queries.
For instance, there are at least 16 system rules that detect suspicious network access events and
incidents, and 15 system reports to report this information. CS-MARS provides a system rule group and
a system report group named “Access” that can filter the Inspection Rules, Incidents, and Report pages
to display only those rules and reports related to monitoring access event (such as password attacks),
thereby eliminating the need to search for the pertinent rules and reports within the complete rule and
report pages or dropdown lists. CS-MARS provides system rule and report groups as listed in
Table 21-2
.
Table 21-2
Predefined Rule and Report Groups
System Report Groups
Corresponding System Rule Groups
System: Access
System: Access
System: All Events - Aggregate View
—
System: All Exploits - Aggregate View
—
System: COBIT DS3.3 - Monitoring and
Reporting
—
System: COBIT DS5.10: Security Violations
—
System: COBIT DS5.19: Malicious software
—
System: COBIT DS5.20: Firewall control
—
System: COBIT DS5.2: Authentication and
Access
—
System: COBIT DS5.4: User Account Changes
—
System: COBIT DS5.7: Security Surveillance
—
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...