
Sentinel Architecture
445
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
Streaming Maps
Map Service employs a dynamic update model and streams the maps from one point to another,
avoiding the build up of large static maps in dynamic memory. The value of this streaming
capability is particularly relevant in a mission-critical real-time system such as Sentinel where there
needs to be a steady, predictive and agile movement of data independent of any transient load on the
system.
Exploit Detection (Mapping Service)
Sentinel provides the ability to cross-reference event data signatures with Vulnerability Scanner
data. Users are notified automatically and immediately when an attack is attempting to exploit a
vulnerable system. This is accomplished through:
Advisor Feed
Intrusion detection
Vulnerability scanning
Firewalls
Advisor provides a cross-reference between event data signatures and vulnerability scanner data.
Advisor feed has an alert and attack feed. The alert feed contains information about vulnerabilities
and threats. The attack feed is a normalization of event signatures and vulnerability plug-ins. For
more information on Advisor, see
Chapter 8, “Advisor Usage and Maintenance,” on page 159
.
You require at least one vulnerability scanner and either an IDS, IPS, or firewall. The IDS and
Firewall DeviceName should appear in the RV31 field of the event. Also, the IDS and Firewall must
properly populate the DeviceAttackName (rt1) field (for example, WEB-PHP Mambo
uploadimage.php access).
The Advisor feed is sent to the database and then to the Exploit Detection Service. The Exploit
Detection Service generates one or two files depending on the kind of data that has been updated.
Figure A-3
Exploit Detection
The Exploit Detection Map Files are used by the Mapping Service to map attacks to exploits of
vulnerabilities.
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...