Symantec 10268947 User Guide - Page 78

About confidence levels, About event sources, About response actions, About SNMP notification

Page 78 highlights

78 Response Rules About automated responses About confidence levels Symantec Network Security indicates the confidence level, a measure of the likelihood of an actual attack. It determines the confidence level of the event by analyzing the traffic behavior. About event sources The Network Security console can apply response rules to specific locations or interfaces in the network using Event Source. The event source parameter indicates that a rule applies only to events detected on a given interface. This interface is not necessarily the target of the attack, but may in fact be the point in the network at which Symantec Network Security is currently tracking the attack. If the interfaces being inspected are receiving VLAN encapsulated traffic, you can also specify that a rule applies to a specific VLAN ID. About response actions The Network Security console provides a way to apply the response rule to take a specific action when triggered using Response Action. The Response parameter determines the action Symantec Network Security takes if an incident matches the event target, attack type, severity, confidence level, and event source parameters. SuperUsers and Administrators can set multiple response actions to react to specific types of incidents, or set custom response actions to launch third-party applications in response to an incident. Note: StandardUsers and RestrictedUsers can view response rules, but cannot apply, edit, or delete them. Symantec Network Security can take the following action or sequence of actions in response to an event that matches the criteria: ■ About no response action ■ About email notification ■ About SNMP notification ■ About TrackBack response action ■ About custom response action ■ About TCP reset response action ■ About traffic record response action ■ About console response action

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

78
Response Rules
About automated responses
About confidence levels
Symantec Network Security indicates the confidence level, a measure of the
likelihood of an actual attack. It determines the confidence level of the event by
analyzing the traffic behavior.
About event sources
The Network Security console can apply response rules to specific locations or
interfaces in the network using Event Source. The event source parameter
indicates that a rule applies only to events detected on a given interface. This
interface is not necessarily the target of the attack, but may in fact be the point
in the network at which Symantec Network Security is currently tracking the
attack. If the interfaces being inspected are receiving VLAN encapsulated
traffic, you can also specify that a rule applies to a specific VLAN ID.
About response actions
The Network Security console provides a way to apply the response rule to take
a specific action when triggered using Response Action. The Response
parameter determines the action Symantec Network Security takes if an
incident matches the event target, attack type, severity, confidence level, and
event source parameters. SuperUsers and Administrators can set multiple
response actions to react to specific types of incidents, or set custom response
actions to launch third-party applications in response to an incident.
Note:
StandardUsers and RestrictedUsers can view response rules, but cannot
apply, edit, or delete them.
Symantec Network Security can take the following action or sequence of actions
in response to an event that matches the criteria:
About no response action
About email notification
About SNMP notification
About TrackBack response action
About custom response action
About TCP reset response action
About traffic record response action
About console response action