Examining your network traffic with forensic analysis
Chapter 9: Forensic Analysis 235
be available from the right-click menu. You can also jump to the
Decode display of the packet that triggered the alert.
Creating a Forensic Settings profile
Forensics profiles provide a mechanism to define and load different pairings of
settings and rules profiles.
Settings profiles
define pre-processor settings that
let you tune performance;
rules profiles
define which forensic rules are to be
processed during analysis to catch threats against particular target operating
systems and web servers. Because Observer performs signature matching on
existing captures rather than in real time, its preprocessor configuration differs
from that of native Snort. When you import a set of Snort rules that includes
configuration settings, Observer imports rules classifications, but uses its own
defaults for the preprocessor settings.
Note:
There is a difference between enabling the preprocessor and enabling
logs for the preprocessor. For example, you can enable IP defragmentation
with or without logging. Without logging, IP fragments are simply
reassembled; only time-out or maximum limit reached messages are noted
in the Forensics Log and in the Forensic Analysis Summary window. If
logging is enabled, all reassembly activity is displayed in the Forensics Log
(but not displayed in the Forensic Analysis Summary).
2.
Click the
Forensic Analysis
tab.
3.
Right-click anywhere on the Forensic Analysis tab and choose Forensic
Settings from the menu. The Select Forensic Analysis Profile window opens.
4.
Choose your profile and click Edit. The Forensic Settings window opens.
5.
From the Forensic Settings window, complete the following:
●
Import Snort rules
●
Define Forensic Settings.
●
Define Rule Settings—Select the rules you want to enable.
6.
Close all of the windows, then right-click anywhere on the Forensic Analysis
tab and choose Analyze from the menu.
applies the rules and filters to the capture data and displays the results in the
Forensics Summary tab.
The top portion of the Rules window lists the rules that were imported,
grouped in a tree with branches that correspond to the files that were
imported.
Rule classifications offer another level of control. Check the “Rules must also
match rule classifications” box to display a list of defined rule classifications.
Classifications are defined at import time by parsing the Snort config
classification statements encountered in the rule set. Rules are assigned a
classification in the rule statement’s classtype option.
Select the rule classification(s) you want to enable. If classification matching is
enabled, a rule and its classification must both be enabled for that rule to be
processed. For example, suppose you want to enable all policy violation rules:
simply right-click on the rule list, choose Enable all rules, and then enable the
policy violation classification.
Содержание Apex Enterprise G3-APEX-ENT-32T
Страница 1: ...Observer GigaStor 17 2 0 0 User Guide 23 Feb 2018 ...
Страница 48: ...G3 GS 8P 288T 48 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 29 G3 GS 8P 288T Front ...
Страница 78: ...GS 2P40 576T 78 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 51 GS 2P40 576T Front ...
Страница 85: ...GS 2P40 288T Chapter 1 Appliance installation 85 Figure 55 GS 2P40 288T Front ...
Страница 86: ...GS 2P40 288T 86 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 56 GS 2P40 288T Rear System ...
Страница 90: ...GS 2P40 288T 90 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 57 GS 2P40 288T Rear ...
Страница 93: ...GS 8P 576T Chapter 1 Appliance installation 93 Figure 59 GS 8P 576T Front ...
Страница 100: ...GS 8P 288T 100 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 101: ...GS 8P 288T Chapter 1 Appliance installation 101 ...
Страница 102: ...GS 8P 288T 102 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 103: ...GS 8P 288T Chapter 1 Appliance installation 103 ...
Страница 104: ...GS 8P 288T 104 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 105: ...GS 8P 288T Chapter 1 Appliance installation 105 ...
Страница 106: ...GS 8P 288T 106 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 107: ...GS 8P 288T Chapter 1 Appliance installation 107 ...
Страница 108: ...GS 8P 288T 108 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 109: ...GS 8P 288T Chapter 1 Appliance installation 109 ...
Страница 110: ...GS 8P 288T 110 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 111: ...GS 8P 288T Chapter 1 Appliance installation 111 Figure 64 GS 8P 288T Rear ...
Страница 112: ...GS 8P 288T 112 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 113: ...GS 8P 288T Chapter 1 Appliance installation 113 ...
Страница 114: ...GS 8P 288T 114 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 115: ...GS 8P 288T Chapter 1 Appliance installation 115 ...
Страница 116: ...GS 8P 288T 116 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 117: ...GS 8P 288T Chapter 1 Appliance installation 117 ...
Страница 118: ...GS 8P 288T 118 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 119: ...GS 8P 288T Chapter 1 Appliance installation 119 ...
Страница 120: ...GS 8P 288T 120 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 124: ...GS 8P 288T 124 GigaStor 23 Feb 2018 Archive Non authoritative version Figure 65 GS 8P 288T Rear ...
Страница 125: ...GS 8P 288T Chapter 1 Appliance installation 125 ...
Страница 126: ...GS 8P 288T 126 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 127: ...GS 8P 288T Chapter 1 Appliance installation 127 ...
Страница 128: ...GS 8P 288T 128 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 129: ...GS 8P 288T Chapter 1 Appliance installation 129 ...
Страница 130: ...GS 8P 288T 130 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 131: ...GS 8P 288T Chapter 1 Appliance installation 131 ...
Страница 132: ...GS 8P 288T 132 GigaStor 23 Feb 2018 Archive Non authoritative version ...
Страница 133: ...GS 8P 288T Chapter 1 Appliance installation 133 ...
Страница 137: ...GS 8P 192T Chapter 1 Appliance installation 137 Figure 67 GS 8P 192T Front ...
Страница 181: ...How to install the SFPs Chapter 1 Appliance installation 181 Figure 101 2U capture card port assignments ...