D-25
User Guide for Cisco Security MARS Local Controller
78-17020-01
Appendix D System Rules and Reports
List of System Reports
This report ranks hosts by the total number of events detecting scanning activity directed to that
host. Scans involve activities such as searching for alive hosts, open services on such hosts and
detecting host configuration and application settings.
•
Activity: Scans - Top Destinations.
Activity: Scans - Top Destinations
•
Activity: Scans - Top Sources.
This report ranks an attack sources by the total number of events detecting scanning activity for
certain services. Scans involve activities such as searching for alive hosts, open services on such
hosts and detecting host configuration and application settings.
•
Activity: Scans - Top Sources.
Activity: Scans - Top Sources
•
Activity: Security Posture: Healthy - Top Users.
This report lists the users in a HEALTHY Security Posture State. A Healthy security posture implies
that the posture of the host is up to date, policy compliant and does not need attention.
•
Activity: Security Posture: Healthy - Top Users.
Activity: Security Posture: Healthy - Top Users
•
Activity: Security Posture: NAC - Top NADs and Tokens.
This report displays the Network Access Devices (NADs) handling Network Admission Control
transcations along with the tokens assigned by each of them.
•
Activity: Security Posture: NAC - Top NADs and Tokens.
This report displays the Network Access Devices (NADs) handling Network Admission Control
transcations along with the tokens assigned by each of them.
•
Activity: Security Posture: NAC - Top NADs.
This report ranks the network access devices (NADs) handling Network Admission Control
transcations.
•
Activity: Security Posture: NAC - Top NADs.
This report ranks the network access devices (NADs) handling Network Admission Control
transcations.
•
Activity: Security Posture: NAC - Top Tokens.
This report shows the network wide distribution of NAC tokens. The possible token values are
HEALTHY, CHECKUP, INFECTED, QUARANTINE, UNKNOWN. The TRANSITION token is
excluded since it is an intermediate state.
•
Activity: Security Posture: NAC - Top Tokens.
This report shows the network wide distribution of NAC tokens. The possible token values are
HEALTHY, CHECKUP, INFECTED, QUARANTINE, UNKNOWN. The TRANSITION token is
excluded since it is an intermediate state.
•
Activity: Security Posture: NAC Agentless - Top Hosts.
This report captures the distribution of NAC tokens for end hosts that do not have Cisco Trust Agent
(CTA) software. In this case, the posture validation is done either locally by the Network Access
Device or via the Audit Server. The possible NAC tokens values in this report are HEALTHY,
CHECKUP, INFECTED, QUARANTINE, UNKNOWN. The TRANSITION token is excluded
since it is an intermediate state.
•
Activity: Security Posture: NAC Agentless - Top Hosts.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...