Symantec 10521146 Administration Guide - Page 173

Saturation Counter Lapse Time, Maximum Time to Streak Analysis, Slow Scan Maximum IP Addresses Limit

Page 173 highlights

Detecting 173 Configuring sensor detection Saturation Counter Lapse Time Saturation Counter Lapse Time regulates the time period to collect packets. The sensor must detect 2,048 packets in the time period set by this parameter and send them to analysis. If traffic moves slower than that, it skips analysis. If traffic exceeds the threshold, then it proceeds to analysis. The default is set to 5 seconds for optimum performance and sensitivity, and does not need to be changed under most circumstances. Valid values range from 0 to 3,600 (1 hour), inclusive. Consider changing it only for troubleshooting purposes, and with thorough knowledge of its functionality. If this parameter is set to lapse too often, such as 1 second, it decreases sensitivity to threshold alerts. It does not directly affect performance, and since it guards low-level threshold, fast traffic remains unaffected. Maximum Time to Streak Analysis Maximum Time to Streak Analysis regulates a periodic analysis, regardless of the number of packets detected, even if the sensor detects very little activity. In this way, it prevents the streak analysis functionality from being too quiet. The default is set to 10 for optimum performance and sensitivity, and does not need to be changed under most circumstances. Valid values range from 0 to 3600, inclusive. Consider changing it only for troubleshooting purposes, and with thorough knowledge of its functionality. Slow Scan Maximum IP Addresses Limit Slow Scan Maximum IP Addresses Limit regulates the number of IP addresses that the sensor monitors for slow scans. This pertains exclusively to port scans, not port sweeps. The default is set to 65,536 for optimum performance and sensitivity, and does not need to be changed under most circumstances. Valid values range from 1 to 1,000,000, inclusive. Consider changing it only for troubleshooting purposes, and with thorough knowledge of its functionality. Changes to this parameter can affect memory consumption. Note: Restart the sensor for changes to this parameter to take effect. Table element parameters The following parameters regulate the size of fragment tables of various types, which directly impacts memory consumption.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392

173
Detecting
Configuring sensor detection
Saturation Counter Lapse Time
Saturation Counter Lapse Time
regulates the time period to collect packets. The
sensor must detect 2,048 packets in the time period set by this parameter and
send them to analysis. If traffic moves slower than that, it skips analysis. If
traffic exceeds the threshold, then it proceeds to analysis.
The default is set to 5 seconds for optimum performance and sensitivity, and
does not need to be changed under most circumstances. Valid values range from
0 to 3,600 (1 hour), inclusive. Consider changing it only for troubleshooting
purposes, and with thorough knowledge of its functionality.
If this parameter is set to lapse too often, such as 1 second, it decreases
sensitivity to threshold alerts. It does not directly affect performance, and since
it guards low-level threshold, fast traffic remains unaffected.
Maximum Time to Streak Analysis
Maximum Time to Streak Analysis
regulates a periodic analysis, regardless of the
number of packets detected, even if the sensor detects very little activity. In this
way, it prevents the streak analysis functionality from being too quiet.
The default is set to 10 for optimum performance and sensitivity, and does not
need to be changed under most circumstances. Valid values range from 0 to
3600, inclusive. Consider changing it only for troubleshooting purposes, and
with thorough knowledge of its functionality.
Slow Scan Maximum IP Addresses Limit
Slow Scan Maximum IP Addresses Limit
regulates the number of IP addresses
that the sensor monitors for slow scans. This pertains exclusively to port scans,
not port sweeps.
The default is set to 65,536 for optimum performance and sensitivity, and does
not need to be changed under most circumstances. Valid values range from 1 to
1,000,000, inclusive. Consider changing it only for troubleshooting purposes,
and with thorough knowledge of its functionality. Changes to this parameter
can affect memory consumption.
Note:
Restart the sensor for changes to this parameter to take effect.
Table element parameters
The following parameters regulate the size of fragment tables of various types,
which directly impacts memory consumption.