Seap; New Features - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Appendix A
System Architecture
Responsibilities and Components
SensorApp performs packet capture and analysis. Policy violations are detected through signatures in
SensorApp and the information about the violations is forwarded to the Event Store in the form of an
alert.
Packets flow through a pipeline of processors fed by a producer designed to collect packets from the
network interfaces on the sensor.
SensorApp supports the following processors:
78-16527-01
SEAP, page A-25
New Features, page A-26
Time Processor (TP)
This processor processes events stored in a time-slice calendar. Its primary task is to make stale
database entries expire and to calculate time-dependent statistics.
Deny Filters Processor (DFP)
This processor handles the deny attacker functions. It maintains a list of denied source IP addresses.
Each entry in the list expires based on the global deny timer, which you can configure in the virtual
sensor configuration.
Signature Event Action Processor (SEAP)
This processor processes event actions. It supports the following event actions:
Reset TCP flow
IP log
Deny packets
Deny flow
Deny attacker
Alert
Block host
Block connection
Generate SNMP trap
Capture trigger packet
Event actions can be associated with an event RR threshold that must be surpassed for the actions
to take place.
Statistics Processor (SP)
This processor keeps track of system statistics such as packet counts and packet arrival rates.
Layer 2 Processor (L2P)
This processor processes layer 2-related events. It also identifies malformed packets and removes
them from the processing path. You can configure actionable events for detecting malformed packets
such as alert, capture packet, and deny packet. The layer 2 processor updates statistics about packets
that have been denied because of the policy you have configured.
Database Processor (DBP)
This processor maintains the signature state and flow databases.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
SensorApp
A-23

Advertisement

Table of Contents
loading

Table of Contents