Security Considerations for Sentinel 6.1 Rapid Deployment
55
no
vd
ocx
(e
n)
17
Sep
te
m
be
r 20
09
Table 5-1
Locations for Configuration Data and Event Data
Components
Location for Configuration Data
Location for Event Data
Sentinel 6.1 Rapid
Deployment Server
Database tables and the file system
(
<
Install_Directory
>/
config
)
This configuration information
includes the encrypted database,
event source, integrators, and
passwords.
Database (EVENTS,
CORRELATED_EVENTS, and
EVT_SMRY_*, AUDIT_RECORD
tables) and the file system at
<
Install_Directory
>/data/
eventdata
and
<
Install_Directory
>/data/raw data
Event data can be archived to the
file system as part of the partition
management job.
Correlation Engine
File system
(
<
Install_Directory
>/
config
). The only sensitive
configuration information is the
client key pair used to connect to the
message bus.
correlation_engine.cache
DAS Core
<
Install_Directory
>/config das_core.cache
DAS Binary
<
Install_Directory
>/config
Event data might be cached if the
database is down
das_binary.cache
Collector Manager
File system
(
<
Install_Directory
>/
config
). The only sensitive
configuration information is the
client key pair used to connect to the
message bus.
Event data might be cached on the
file system during error conditions
such as the message bus being
down or event overflow. This event
data is stored in the
<
Install_Directory
>/data/
collector_mgr.cache
directory
Client Applications
File system
(
Install_Directory
/config
).
The client applications don't store
any sensitive information in their
configuration files .
For example, client applications can
export ESM data to a local file
system. The exported file contains
encrypted passwords, if they are
present in the configuration of the
event sources that were exported.
Although the passwords are
encrypted, the ESM export
permission should only be given to
users that can be trusted with this
privilege.
None
Содержание Sentinel Rapid Deployment 6.1
Страница 4: ...4 Sentinel 6 1 Rapid Deployment Installation Guide novdocx en 17 September 2009 ...
Страница 8: ...8 Sentinel 6 1 Rapid Deployment Installation Guide novdocx en 17 September 2009 ...
Страница 22: ...22 Sentinel 6 1 Rapid Deployment Installation Guide novdocx en 17 September 2009 ...
Страница 72: ...72 Sentinel 6 1 Rapid Deployment Installation Guide novdocx en 17 September 2009 ...
Страница 78: ...78 Sentinel 6 1 Rapid Deployment Installation Guide novdocx en 17 September 2009 ...