Symantec 10521146 Administration Guide - Page 171
Streak Interval, TCP Minimum Flows, TCP Number of Streak Packets
UPC - 037648268134
View all Symantec 10521146 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 171 highlights
Detecting 171 Configuring sensor detection Streak Interval Streak Interval regulates how often the sensor checks traffic for port scans. In past versions, Streak Interval and Counter Interval were controlled by the same parameter. Symantec Network Security now provides two parameters that you can configure independently. The default is set to 16,383 for optimum sensitivity and performance, and does not need to be changed under most circumstances. Valid values range from 1,023 to 16,383, inclusive. You can increase sensitivity to port scans by lowering the value so that the sensor checks more often. Do not make changes to this parameter without a thorough understanding of how it interacts with TCP Minimum Flows, UDP Minimum Flows, TCP Number of Streak Packets, and UDP Number of Streak Packets. Note: In versions prior to 4.0, Streak Interval and Counter Interval were controlled by the same parameter. Symantec Network Security now provides two parameters that you can configure independently. TCP Minimum Flows TCP Minimum Flows regulates the number of unacknowledged TCP flows that the sensor sends to analysis during the time period set by Streak Interval. If it detects an alarming number of them, it sends the packets to streak analysis, which inspects the sample of packets and compares IP addresses, ports, and other characteristics for similarities. The default is set to 3 for optimum sensitivity and performance, and does not need to be changed under most circumstances. Valid values range from 3 to twice the value of the TCP Number of Streak Packets parameter. Increasing the value will decrease sensitivity. This parameter should not be changed without a thorough understanding of how it interacts with Streak Interval and TCP Number of Streak Packets. UDP Minimum Flows UDP Minimum Flows regulates the number of unacknowledged UDP flows that the sensor sends to analysis during the time period set by Streak Interval. If it detects an alarming number of them, it sends the packets to streak analysis, which inspects the sample of packets and compares IP addresses, ports, and other characteristics for similarities. The default is set to 3 for optimum sensitivity and performance, and does not need to be changed under most circumstances. Valid values range from 3 to twice the value of the UDP Number of Streak Packets parameter.