D-6
User Guide for Cisco Security MARS Local Controller
78-17020-01
Appendix D System Rules and Reports
List of System Rules
•
System Rule: Network Errors - Likely Routing Related.
This rule detects a large frequency of denied packets or ICMP destination unreachable events
between the same source, destination pair - this may indicate a network routing error and may be
caused by periodic retransmission attempts by TCP or the application itself (e.g. DNS).
•
System Rule: New Malware Discovered.
This rule detects that Cisco Incident Control Server (ICS) has received information about a new
virus/worm/malware outbreak. ICS is going to deploy ACLs or signatures to routers and IPS devices
•
System Rule: New Malware Prevention Deployed.
This rule detects that Cisco Incident Control Server (ICS) has successfully deployed ACLs or
signatures to routers and IPS devices in an attempt to prevent a newly discovered
virus/worm/malware outbreak.
•
System Rule: New Malware Prevention Deployment Failed.
This rule detects that Cisco Incident Control Server (ICS) has failed to deploy ACLs or signatures
to routers and IPS devices for preventing a new virus/worm/malware outbreak.
•
System Rule: New Malware Traffic Match.
This correlated rule detects a traffic pattern that (a) matches a worm pattern: same source to many
distinct destinations and (b) matches the ACLs and signatures deployed by Cisco Incident Control
Server (ICS) in response to a newly discovered virus/worm/malware outbreak.
•
System Rule: Operational Issue: Firewall.
This rule detects operational errors (e.g. bad network connectivity, failover errors, internal
software/hardware errors) reported by a firewall - this may indicate that the firewall is not
functioning properly.
•
System Rule: Operational Issue: IDS.
This rule detects operational errors reported by a intrusion detection system (IDS) - this may
indicate that the device is not functioning properly.
•
System Rule: Operational Issue: Router / Switch.
This rule detects operational errors reported by non-security network devices such as routers and
switches.
•
System Rule: Operational Issue: Server.
This rule detects operational errors reported by a host or by applications on a host - this may indicate
that either the host or the specific application on the host is not functioning properly.
•
System Rule: Password Attack: Database - Attempt.
This correlation rule detects a password guessing attack to a database server, preceded by
reconnaissance attacks to the host, if any. A password guessing attack consists of multiple login
failures and may sometimes be caused by a user forgetting the password.
•
System Rule: Password Attack: Database - Success Likely.
This correlation rule detects a password guessing attack on a database server followed by a
successful logon. The attack may be preceded by reconnaissance attacks to the host. A password
guessing attack consists of multiple login failures and may sometimes be caused by a user forgetting
the password.
•
System Rule: Password Attack: Disabled Accounts.
This rule detects repeated failed password attempts on locked, expired or disabled accounts on a host
•
System Rule: Password Attack: FTP Server - Attempt.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...