
458
Sentinel 6.1 User Guide
no
vd
ocx
(e
n)
7 Ja
nua
ry 201
0
correlation engine works with a rules checker component which computes the correlation rule
expressions and validates syntax of filters. In addition to providing a comprehensive set of
correlation rules, Sentinel’s correlation engine provides specific advantages over database-centric
correlation engines.
By relying on in-memory processing rather than database inserts and reads, the correlation
engine performs during high steady-state volumes as well as during event spikes when under
attack, the time when correlation performance is most critical.
Correlation volume does not slow down other system components, so the user interface
remains responsive, especially with high event volumes.
Distributed correlation: Organizations can deploy multiple correlation engines, each on its own
server, without the need to replicate configurations or add databases. Independent scaling of
components provides cost-effective scalability and performance.
The correlation engine can add events to incidents after an incident has been determined.
Users are encouraged to measure a metric called Event Rules per Second (ERPS). ERPS is the
measure of the number of events that can be examined by a correlation rule per second. This
measure is a good performance indicator as it estimates the impact on performance when two factors
intersect: events per second and number of rules in use.
Dynamic Lists:
Dynamic lists are distributed list structures that can be used for storing
elements and performing fast lookups on those elements. These lists can store a set of strings
such as IP addresses, server names or usernames. Examples of dynamic lists include:
Terminated user list
Suspicious user watch list
Privileged user watch list
Authorized ports and services list
Authorized server list
In all cases, correlation rules might reference named dynamic lists to perform lookups on list
members. For example, a rule can be written to identify a file access event from a user who is
not a member of the Authorized Users list. Additionally, correlation actions integrate with the
dynamic list module to add or remove elements from a list. The combination of lookups and
automated actions on the same list provides a powerful feedback mechanism used to identify
complex situations.
Workflow Service (iTRAC)
The Workflow Service receives triggers on incident creation and initiates workflow processes based
on pre-defined workflow templates. It manages the lifecycle of these processes by generating work
items or executing activities. This service also maintains a history of completed processes that can
be used for auditing incident responses.
Event Visualization
Active Views
TM
, the interactive graphical user interface for event visualization, provides an
integrated, security management dashboard with a comprehensive set of real-time visualization and
analytical tools to facilitate threat detection and analysis. Users can monitor events in real time and
perform instant drill-downs from seconds to hours in the past. A wide array of visualization charts
and aids allow monitoring of information through 3D bar, 2D stacked, line and ribbon chart
Содержание SENTINEL 6.1 SP2
Страница 4: ...4 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 20: ...20 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 34: ...34 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 57: ...Active Views Tab 57 novdocx en 7 January 2010 Figure 2 7 Organic View Figure 2 8 Hierarchical View ...
Страница 97: ...Incidents Tab 97 novdocx en 7 January 2010 Sort By You can set rules to sort the incidents in the display view ...
Страница 116: ...116 Sentinel 6 1 User Guide novdocx en 7 January 2010 Integer Variable String Variable ...
Страница 146: ...146 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 172: ...172 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 178: ...178 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 280: ...280 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 306: ...306 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 329: ...Quick Start 329 novdocx en 7 January 2010 ...
Страница 330: ...330 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 401: ...Sentinel Link Solution 401 novdocx en 7 January 2010 3 Select the Novell Sentinel Link Collector then click Next ...
Страница 405: ...Sentinel Link Solution 405 novdocx en 7 January 2010 6 In the Configure Connector window specify the following ...
Страница 412: ...412 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 430: ...430 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...
Страница 440: ...440 Sentinel 6 1 User Guide novdocx en 7 January 2010 Figure 18 3 Reports ...
Страница 528: ...528 Sentinel 6 1 User Guide novdocx en 7 January 2010 ...