Correlation - Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual

Table of Contents

Advertisement

10 In the Work Items window, select the process and click View Details. The Collect Data step
should be highlighted in red. As before, this is a manual step.
11 Click the Process Details tab.
12 Again, the variable page displays. In the previous step of the iTRAC Process, Collect Data is a
step to further determine by analyzing the events of interest if an attack has occurred. For
example, assume that an attack has occurred. Leave the default value of yes. If this were a real
attack, it is beneficial to add clear notes or attachments as to the information about this attack.
13 Click Complete.
14 In Work Items window, select the process and click View Details. The Prevent Future Attacks
step should be highlighted in red. As before, this is a manual step.
15 In this manual step, take measures to harden the network to prevent future attacks. When this is
done, you should add notes and attachments as to the information about this attack.
16 Click Complete.
The next step is an automatic e-mail step indicating that proper anti-attack measures have been
taken. The iTRAC Process is removed from the Work Items window.
If you go to the Process View window or if you double-click this process, it appears as
Complete.

13.4 Correlation

Correlation is the process of analyzing security events to identify potential relationships between
two or more events. Correlation allows quick association of priority attacks based on common
elements of event data.
The following example is written for the Data Generator Connector that comes installed in Sentinel
as a test event generator.
NOTE: Anytime the Data Generator Connector is running, it adds data into your database. Using a
correlation rule that is associated with the Data Generator Connector also adds additional data to
your database.
Section 13.4.1, "Creating a Simple Correlation Rule," on page 309
Section 13.4.2, "Deploying the Simple Correlation Rule," on page 309
Section 13.4.3, "Viewing the Events that Triggered Your Correlated Event," on page 310
308 Sentinel 6.1 Rapid Deployment User Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents