Figure 10-2: Bsc Ids Host State Model - ADTRAN BlueSecure Controller Setup And Administration Manual

Software release version: 6.5
Table of Contents

Advertisement

Chapter 10: General BSC Operational Settings
Normal State
By default, a user host will start in the Normal State unless or otherwise blocked. The
administrator-configurable parameter
used to define the bounds of normal traffic. If a user host exceeds this maximum, i.e., if it
tries to make too many connections to the BSC, the IDS records a violation for the host. If
the host's violation count exceeds the
host's state to Pre-monitoring.
Pre-monitoring
In this state the IDS tracks the host's violations of the
State
accrues more violations than specified in the
transitions the host to the Monitoring State. If the host does not exceed the
of Violations
IDS returns the host to the Normal State.
Monitoring State
If a host progresses all the way from the Normal to the Monitoring state, there is a high
probability that it may be involved in some abnormal activity. While a host is in this state,
the IDS blocks all problematic host ports immediately, identifies the type of attack, and
takes additional actions as necessary. The possible necessary actions include blocking
traffic on one or more additional host ports, or blocking all traffic from the host. A user
accessing the BSC via a host in the Monitoring state will be redirected to the URL
specified by the
any further abnormal activity from the host, the IDS will transition the host back to the Pre-
monitoring State.
A host in the Monitoring state is able to send normal traffic on all ports with the exception
of those ports that have been blocked. All dropped packets are tallied.
The BSC IDS will transition the host from the Monitoring State to the Blocked State once
the number of ports specified in the
are blocked, or if the host continues to make too many connection attempts. If the
block before entering Blocked State
transition the host from the Monitoring state to the Blocked state.
Blocked State
Once a user host enters into this state, the MAC of the host is noted and the blocked user
is placed into the Administrator-selected IDS role. You may select only a single IDS role for
users in the Blocked State. There are two default IDS roles from which to select—
Monitoring Mode (allow all traffic) or Quarantined (deny all traffic). You may customize
10-6
Blocked

Figure 10-2: BSC IDS Host State Model

within the period of time specified by the
URL to redirect detected devices
Normal
Monitoring
Maximum Number of Firewall Sessions per user
Violation Threshold
setting, the IDS transitions the
Violation Threshold
Max Number of Violations
Pre-monitoring Timeout
setting. If the BSC IDS does not detect
Ports to block before entering Blocked State
setting is set to zero, the IDS will immediately
Pre-monitoring
is
setting. If the host
setting, the IDS
Max Number
setting, the
setting
Ports to

Advertisement

Table of Contents
loading

Table of Contents