Host Reputation; Configuration" Tab; General; Alarms - Stormshield SN series Configuration Manual

Hide thumbs Also See for SN series:
Table of Contents

Advertisement

HOST REPUTATION

This feature, which can be combined with geolocation, makes it possible to lower an
organization's attack risk.
Using his security policy, the administrator can block the connections of hosts with a bad
reputation.
Three criteria are taken into account when calculating a host's reputation:
minor and major alarms generated by the host,
l
the results of the sandboxing analysis of files exchanged by the host,
l
the results of the antivirus analysis of files hosted and passing through the host,
l

"Configuration" tab

This tab makes it possible to enable host reputation management and define the respective
weight of the various criteria involved in the calculation of a reputation.

General

Enable dynamic host
reputation
management

Alarms

Major [0-20]
Minor [0-20]

Antivirus

Infected [0-100]
Unknown
Scan failed

Sandboxing

Malicious [0-100]
Suspicious [0-100]
Scan failed [0-20]
Page 153/448
This checkbox makes it possible to enable or disable the calculation of the reputation
of hosts on the internal network.
Adjust the slider in order to define the weight of major alarms raised by a host in the
calculation of its reputation.
Adjust the slider in order to define the weight of minor alarms raised by a host in the
calculation of its reputation.
Adjust the slider in order to define the weight of infected files detected by the
antivirus scan in the calculation of a host's reputation.
Adjust the slider in order to define the weight of unknown files detected by the
antivirus scan in the calculation of a host's reputation.
Adjust the slider in order to define the weight of files that could not be scanned by the
antivirus in the calculation of a host's reputation.
Adjust the slider in order to define the weight of malicious files detected for this host
in the calculation of a host's reputation.
Adjust the slider in order to define the weight of suspicious files detected for this host
in the calculation of a host's reputation.
Adjust the slider in order to define the weight of files that could not be scanned by
sandboxing in the calculation of a host's reputation.
SNS - USER CONFIGURATION MANUAL V.3
sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
HOST REPUTATION

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents