D-24
User Guide for Cisco Security MARS Local Controller
78-17020-01
Appendix D System Rules and Reports
List of System Reports
This event ranks events detecting person-to-person file sharing protocol and chat protocol activity.
File sharing protocols such as KaZaa, Napster, EDonkey and chat protocols such as IRC, Hotline
and instant messaging protocols may not be suitable in business environments.
•
Activity: P2P Filesharing/Chat - Top Event Types.
Activity: P2P Filesharing/Chat - Top Event Types
•
Activity: P2P Filesharing/Chat - Top Hosts.
This report ranks hosts involved in P2P Filesharing and chat protocol activity. Such protocols may
not be suitable in business environments.
•
Activity: P2P Filesharing/Chat - Top Hosts.
Activity: P2P Filesharing/Chat - Top Hosts
•
Activity: Recreational - All Events.
This event details all users involved in recreational activities such as games, specific web sites such
as gambling etc.
•
Activity: Recreational - All Events.
This event details all users involved in recreational activities such as games, specific web sites such
as gambling etc.
•
Activity: Recreational - Top Sources.
This report ranks the source addesses involved in recreational activities such as games, adult web
sites, stock sites etc.
•
Activity: Recreational - Top Sources.
Activity: Recreational - Top Sources
•
Activity: Remote Access Login - All Events.
This report details of remote access login events (IPSec, SSLVPN, PPP, L2TP etc)
•
Activity: Remote Access Login - All Events.
This report details of remote access login events (IPSec, SSLVPN, PPP, L2TP etc)
•
Activity: Remote Access Login - Top User.
This report ranks users by remote access logins (PPP, L2TP, PPTP, IPSec).
•
Activity: Remote Access Login - Top User.
This report ranks users by remote access logins (PPP, L2TP, PPTP, IPSec).
•
Activity: Remote Access Login Failures - All Events.
This event details all failed remote access login event details.
•
Activity: Remote Access Login Failures - All Events.
This event details all failed remote access login event details.
•
Activity: Scans - Top Destination Ports.
This report ranks destination ports by the total number of events detecting scanning activity for that
port. Scans involve activities such as searching for alive hosts, open services on such hosts and
detecting host configuration and application settings.
•
Activity: Scans - Top Destination Ports.
Activity: Scans - Top Destination Ports
•
Activity: Scans - Top Destinations.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...