
310
Sentinel 6.1 User Guide
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
3
Click Save. Highlight your filter and click Select.
4
Provide your time period of interest; click Search (Magnifying Glass icon). The result of your
query displays. If your Event Query makes a match, you will get a result similar to the
following illustration.
If you want to see how often in general this user is attempting a telnet, remove DestinationIP,
SensorType and Severity from your filter or create a new filter. The results will show all the
destinationIPs this user is attempting to telnet to.
If any of your events are correlated events, you can right-click > View Trigger Events to find
what events triggered that correlated event.
NOTE:
Correlated events will have the SensorType column populated with a C.
More Information about Attacks
Another event of interest could be excessive FTP events. This can also be a remote connection,
allowing for transferring, copying and deleting of files.
Below is a short list of attacks of interest. Types of attacks are an extensive list. For more
information about network/host attacks, there are many resources available (that is, books and the
internet) that explain different types of attacks in detail.
14.2 Creating Incidents
NOTE:
To perform this function you must have user permission to create Incidents.
This is useful in grouping a set of events together as a whole representing something of interest
(group of similar events or set of different events that indicate a pattern of interest such as an attack).
SourceIP = 10.0.0.3
EventName = Attempted_telnet
Severity = 5
SensorType = H
DestinationIP = 10.0.0.4
Match if, select All conditions are met (and)
SYN Flood
ICMP and UDP Flood
Packet Sniffing
Denial of Service
Smurf and Fraggle
Dictionary Attack
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...