Chapter
5
Protection Policies
This chapter includes the following topics:
■
About protection policies
■
Viewing protection policies
■
Adjusting the view of event types
About protection policies
Symantec Network Security provides a new functionality called protection
policies, which utilize multiple components such as signature and protocol
anomaly detection to take action directly at the point of entry into the network.
Protection policies enable users to tailor the protection based on security
policies and business need. Policies can be tuned by threat category, severity,
intent, reliability, and profile of protected resources. Common or individualized
policies can be applied per sensor, for both in-line and passive monitoring.
The Symantec Network Security software and the Symantec Network Security
7100 Series appliance employ a common core architecture that provides
detection, analysis, storage, and response functionality. Most procedures in this
section apply to both the 7100 Series appliance and the Symantec Network
Security 4.0 software. The 7100 Series appliance also provides additional
functionality that is unique to an appliance. Each section describes this
additional functionality in detail.
For example, when the 7100 Series appliance is deployed in-line, it can perform
session-based blocking against malicious traffic and prevent attacks from
reaching their targets.
Содержание 10268947 - Network Security 7160
Страница 1: ...Symantec Network Security User Guide...
Страница 18: ...18 Introduction Finding information...
Страница 34: ...34 Architecture About management and detection architecture...
Страница 46: ...46 Getting Started About deploying node clusters...
Страница 64: ...64 Topology Database Viewing objects in the topology tree...
Страница 124: ...124 Log Files About log files...
Страница 134: ...134 Index...