2-30
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 2 Reporting and Mitigation Devices Overview
Data Enabling Features
•
return information that determines if the attack failed
•
return information that determines if the attack likely succeeded
•
return false positive information
•
assign severity to firing events and incidents
Select a Network for Scanning
To select a network for scanning, follow these steps:
Step 1
Click the
Select
radio button.
Step 2
Click a network to scan.
Step 3
Click
Add
.
Step 4
Repeat
Step 1
through
Step 3
.
Step 5
Click
Submit
when ready.
Create a Network IP Address for Scanning
To create a network address that you can use to define the scan settings, follow these steps:
Step 1
Click the
Network IP
radio button.
Step 2
Enter the Network IP address and Mask.
Step 3
Click
Add
.
Create a Network IP Range for Scanning
To create a range of network addresses that you can use to define the scan settings, follow these steps:
Step 1
Click the
IP Range
radio button.
Step 2
Enter the range of IP addresses.
Step 3
Click
Add
.
Understanding NetFlow Anomaly Detection
NetFlow is a Cisco technology that supports monitoring network traffic and is supported on all basic IOS
images. NetFlow uses an UDP-based protocol to periodically report on flows seen by the Cisco IOS
device. A
flow
is a Layer 7 concept that consists of a session set up, data transfer, and session teardown.
For every flow, a NetFlow-enabled device record several flow parameters including
•
Flow identifiers, specifically source and destination addresses, ports, and protocol
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...