Symantec 10268947 User Guide - Page 105

Saving incident data, Incidents

Page 105 highlights

Incidents and Events 105 Managing the incident/event data ■ Customer ID This is the customer ID entered in the topology for the interface where the event was detected. ■ End Time The time at which Network Security stopped monitoring the event. ■ CVE Number The CVE (Common Vulnerabilities and Exposures) number, if any. CVE numbers are a list of standardized names for vulnerabilities and other information security exposures compiled by the MITRE Corporation. For a complete list of CVE numbers, see http://cve.mitre.org. ■ Priority The priority level assigned to the incident by the Analysis Framework. The priority level is a function of the severity and reliability levels. ■ Severity The severity level Network Security assigned to the incident. An incident's severity is a measure of the potential damage that an incident can cause. Severity levels range from 0 to 255, with 255 as the most severe. ■ Reliability The reliability level Network Security assigned to the incident. The reliability value indicates the level of certainty that a particular incident is actually an attack. If the incident is merely suspicious, then its assigned reliability level is low. If Network Security collects more data on the incident to substantiate its reliability, the reliability is adjusted upward. Reliability levels range from 0 to 255, with 255 as the most reliable. ■ Attack Source(s) The IP address of the packet that triggered the event. Click the address to view related host name or flow statistics. ■ Attack Destination(s) The IP address of the event's target. Click the address to view related host name or flow statistics. Note: StandardUsers can view detailed information about each incident; RestrictedUsers cannot. Saving incident data All users can save detailed information about each incident on the Network Security console Incidents tab. To save incident data 1 In the Network Security console, click the Incidents tab.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

105
Incidents and Events
Managing the incident/event data
Note:
StandardUsers can view detailed information about each incident;
RestrictedUsers cannot.
Saving incident data
All users can save detailed information about each incident on the Network
Security console Incidents tab.
To save incident data
1
In the Network Security console, click the
Incidents
tab.
Customer ID
This is the customer ID entered in the topology for the
interface where the event was detected.
End Time
The time at which Network Security stopped monitoring the
event.
CVE Number
The CVE (Common Vulnerabilities and Exposures) number,
if any. CVE numbers are a list of standardized names for
vulnerabilities and other information security exposures
compiled by the MITRE Corporation. For a complete list of
CVE numbers, see
.
Priority
The priority level assigned to the incident by the Analysis
Framework. The priority level is a function of the severity
and reliability levels.
Severity
The severity level Network Security assigned to the
incident. An incident’s severity is a measure of the potential
damage that an incident can cause. Severity levels range
from 0 to 255, with 255 as the most severe.
Reliability
The reliability level Network Security assigned to the
incident. The reliability value indicates the level of
certainty that a particular incident is actually an attack. If
the incident is merely suspicious, then its assigned
reliability level is low. If Network Security collects more
data on the incident to substantiate its reliability, the
reliability is adjusted upward. Reliability levels range from 0
to 255, with 255 as the most reliable.
Attack Source(s)
The IP address of the packet that triggered the event. Click
the address to view related host name or flow statistics.
Attack
Destination(s)
The IP address of the event’s target. Click the address to
view related host name or flow statistics.