2-6
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 2 Reporting and Mitigation Devices Overview
Selecting the Devices to Monitor
Network IDS/IPS
Fired signature alerts.
Identifies attacks and
threats, which helps determine mitigation
response, identify potential false positive
information, and target vulnerability assessment
probes conducted by MARS.
Trigger packet information.
Provides the
payload of the packet that caused the signature to
fire.
Determine whether an attack was blocked at a
specific device.
Device status information
Host IDSes
Provides host-level validation of exploits and
blocked attacks, which improves the accuracy of
false positive identification, which in turn
improves the ability of the administrator to
accurately prioritize the work required to contain
attacks.
Anti-Virus
Central anti-virus management servers provide
information on which hosts are infected, which
hosts have reported attempted infections, etc. The
servers also provide the dat or signature file
information for managed hosts, which improves
the ability to determine whether an attack was
likely to have succeeded.
Vulnerability
Assessment
Host OS and Patch Level.
When a signature fires
on an IDS and it is reported to MARS, MARS can
either launch a targeted scan using Nessus, or
query a vulnerability assessment system that
helps determine whether the target was
vulnerable.
Enable any vulnerability assessment solutions
supported by MARS.
Table 2-2
Device Types and Data Available (continued)
Device Type
Data Available
Recommended Configurations
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...