D-7
User Guide for Cisco Security MARS Local Controller
78-17020-01
Appendix D System Rules and Reports
List of System Rules
This correlation rule detects a password guessing attack to an FTP server, preceded by
reconnaissance attacks to the host, if any. A password guessing attack consists of multiple login
failures and may sometimes be caused by a user forgetting the password.
•
System Rule: Password Attack: FTP Server - Success Likely.
This correlation rule detects a password guessing attack on a FTP server followed by a successful
logon. The attack may be preceded by reconnaissance attacks to the host. A password guessing
attack consists of multiple login failures and may sometimes be caused by a user forgetting the
password.
•
System Rule: Password Attack: Mail Server - Attempt.
This correlation rule detects a password guessing attack on a mail server (SMTP, POP, IMAP),
preceded by reconnaissance attacks to the host, if any. A password guessing attack consists of
multiple login failures and may sometimes be caused by a user forgetting the password.
•
System Rule: Password Attack: Mail Server - Success Likely.
This correlation rule detects a password guessing attack on a mail server (SMTP, POP, IMAP)
followed by a successful logon. The password attack may be preceded by reconnaissance attacks to
the host. A password guessing attack consists of multiple login failures and may sometimes be
caused by a user forgetting the password.
•
System Rule: Password Attack: Misc. Application - Attempt.
This correlation rule detects attempts to retrieve application passwords or multiple login failures
while authenticating to a particular application. These attempts can be optionally preceded by
reconnaissance attempts. Authentication failures may sometimes be caused by a user forgetting the
password. The applications covered by this rule exclude common ones such as Mail, FTP, SSH,
Telnet, SNMP, Network/File/Print share, for which there are special rules.
•
System Rule: Password Attack: Network Share - Attempt.
This correlation rule detects a password guessing attack on a network share, preceded by
reconnaissance attacks, if any. A password guessing attack consists of multiple login failures and
may sometimes be caused by a user forgetting the password.
•
System Rule: Password Attack: Network Share - Success Likely.
This correlation rule detects a password guessing attack on a network share, followed by a
successful logon. The password attack may be preceded by reconnaissance attacks to the host. A
password guessing attack consists of multiple login failures and may sometimes be caused by a user
forgetting the password.
•
System Rule: Password Attack: Remote VPN Access - Attempt.
This correlation rule detects a password guessing attack while authenticating to a remote access
service (e.g. Windows L2TP, PPTP based RAS, IPSec etc.), preceded by reconnaissance attacks, if
any. A password guessing attack consists of multiple login failures and may sometimes be caused
by a user forgetting the password.
•
System Rule: Password Attack: Remote VPN Access - Success Likely.
This correlation rule detects a password guessing attack while authenticating to a remote access
service (e.g. Windows L2TP, PPTP based RAS, IPSec etc.), followed by a successful logon. A
password guessing attack consists of multiple login failures and may sometimes be caused by a user
forgetting the password.
•
System Rule: Password Attack: SNMP - Attempt.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...