Examining your network traffic with forensic analysis
Chapter 9: Forensic Analysis 239
Field
Description
Normalize directory traversal—Directory traversal attacks
attempt to access unauthorized directories and commands on
a web server or application by using the /./ and /../ syntax. This
preprocessor removes directory traversals and self-referential
directories. You may want to disable logging for occurrences
of this, as many web pages and applications use directory
traversals to reference content.
Normalize multiple slashes to one—Another directory traversal
strategy is to attempt to confuse the web server with excessive
multiple slashes.
Normalize Backslash—This option emulates IIS treatment of
backslashes (i.e., converts them to forward slashes).
ARP Inspection
Ethernet uses Address Resolution Protocol (ARP) to map IP
addresses to a particular machine (MAC) addresses. Rather
than continuously broadcasting the map to all devices on the
segment, each device maintains its own copy, called the ARP
cache, which is updated whenever the device receives an ARP
Reply. Hackers use cache poisoning to launch man-in-the-
middle and denial of service (DoS) attacks. The ARP inspection
preprocessor examines ARP traffic for malicious forgeries (ARP
spoofing) and the traffic resulting from these types of attacks.
Log preprocessor events—Checking this box causes forensic
analysis to save any alerts generated by the ARP Inspection
preprocessor to the log, but not the Forensic Summary Window.
Report non-broadcast requests—Non-broadcast ARP traffic
can be evidence of malicious intent. Once scenario is the hacker
attempting to convince a target computer that the hacker’s
computer is a router, thus allowing the hacker to monitor all
traffic from the target. However, some devices (such as printers)
use non-broadcast ARP requests as part of normal operation.
Start by checking the box to detect such traffic; disable the
option only if analysis detects false positives.
Telnet
Normalization
Hackers may attempt to evade detection by inserting control
characters into Telnet and FTP commands aimed at a target. This
pre-processor strips these codes, thus normalizing all such traffic
before subsequent forensic rules are applied.
Log preprocessor events—Checking this box causes
forensic analysis to save any alerts generated by the Telnet
Normalization preprocessor to the log, but not the Forensic
Summary Window.
Port List—Lets you specify a list of ports to include or exclude
from Telnet pre-processing. The default settings are appropriate
for most networks.
Variable Name
A scrollable window located below the preprocessor settings
lists the variables that were imported along with the Snort rules.
Variables are referenced by the rules to specify local and remote
network ranges, and common server IP addresses and ports. You
can edit variable definitions by double-clicking on the variable
you want to edit.
The VRT Rule Set variable settings (and those of most publicly-
distributed rule sets) will work on any network without
modification, but you can dramatically improve performance
by customizing these variables to match the network being
Содержание Apex Enterprise G3-APEX-ENT-32T
Страница 1: ...Observer GigaStor 17 2 0 0 User Guide 23 Feb 2018 ...
Страница 48: ...G3 GS 8P 288T 48 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 29 G3 GS 8P 288T Front ...
Страница 78: ...GS 2P40 576T 78 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 51 GS 2P40 576T Front ...
Страница 85: ...GS 2P40 288T Chapter 1 Appliance installation 85 Figure 55 GS 2P40 288T Front ...
Страница 86: ...GS 2P40 288T 86 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 56 GS 2P40 288T Rear System ...
Страница 90: ...GS 2P40 288T 90 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 57 GS 2P40 288T Rear ...
Страница 93: ...GS 8P 576T Chapter 1 Appliance installation 93 Figure 59 GS 8P 576T Front ...
Страница 100: ...GS 8P 288T 100 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 101: ...GS 8P 288T Chapter 1 Appliance installation 101 ...
Страница 102: ...GS 8P 288T 102 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 103: ...GS 8P 288T Chapter 1 Appliance installation 103 ...
Страница 104: ...GS 8P 288T 104 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 105: ...GS 8P 288T Chapter 1 Appliance installation 105 ...
Страница 106: ...GS 8P 288T 106 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 107: ...GS 8P 288T Chapter 1 Appliance installation 107 ...
Страница 108: ...GS 8P 288T 108 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 109: ...GS 8P 288T Chapter 1 Appliance installation 109 ...
Страница 110: ...GS 8P 288T 110 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 111: ...GS 8P 288T Chapter 1 Appliance installation 111 Figure 64 GS 8P 288T Rear ...
Страница 112: ...GS 8P 288T 112 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 113: ...GS 8P 288T Chapter 1 Appliance installation 113 ...
Страница 114: ...GS 8P 288T 114 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 115: ...GS 8P 288T Chapter 1 Appliance installation 115 ...
Страница 116: ...GS 8P 288T 116 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 117: ...GS 8P 288T Chapter 1 Appliance installation 117 ...
Страница 118: ...GS 8P 288T 118 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 119: ...GS 8P 288T Chapter 1 Appliance installation 119 ...
Страница 120: ...GS 8P 288T 120 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 124: ...GS 8P 288T 124 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 65 GS 8P 288T Rear ...
Страница 125: ...GS 8P 288T Chapter 1 Appliance installation 125 ...
Страница 126: ...GS 8P 288T 126 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 127: ...GS 8P 288T Chapter 1 Appliance installation 127 ...
Страница 128: ...GS 8P 288T 128 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 129: ...GS 8P 288T Chapter 1 Appliance installation 129 ...
Страница 130: ...GS 8P 288T 130 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 131: ...GS 8P 288T Chapter 1 Appliance installation 131 ...
Страница 132: ...GS 8P 288T 132 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 133: ...GS 8P 288T Chapter 1 Appliance installation 133 ...
Страница 137: ...GS 8P 192T Chapter 1 Appliance installation 137 Figure 67 GS 8P 192T Front ...
Страница 181: ...How to install the SFPs Chapter 1 Appliance installation 181 Figure 101 2U capture card port assignments ...