Rule And Report Group Overview - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Chapter 21
Rules

Rule and Report Group Overview

To view a list of all System Inspection rules and reports, see
Note
Rule and report groups help you manage rules and reports by speeding access to those rules and reports
relevant to your task at hand. You can create groups, or use the groups provided with CS-MARS (System
groups). Groups act as filters to limit the display of rules, reports, and incidents in the CS-MARS HTML
interface. All groups can be modified or deleted.
CS-MARS provides over 100 system rules and 150 system reports. More can be added by creating
custom rules and reports, and by performing periodic software updates. A rule or report group contains
a subset of these rules or reports as members. Usually rules or reports within the same group have related
functions (such as, reconnaissance activities, server attack, etc.). When you select a group from a
dropdown filter, only those rules and reports that are members are displayed on the page. When you
select a rule group on the Incidents page, only those incidents related to the rules of the selected group
display. Report and rule groups can also be used when constructing queries.
For instance, there are at least 16 system rules that detect suspicious network access events and
incidents, and 15 system reports to report this information. CS-MARS provides a system rule group and
a system report group named "Access" that can filter the Inspection Rules, Incidents, and Report pages
to display only those rules and reports related to monitoring access event (such as password attacks),
thereby eliminating the need to search for the pertinent rules and reports within the complete rule and
report pages or dropdown lists. CS-MARS provides system rule and report groups as listed in
Table 21-2
System Report Groups
System: Access
System: All Events - Aggregate View
System: All Exploits - Aggregate View
System: COBIT DS3.3 - Monitoring and
Reporting
System: COBIT DS5.10: Security Violations
System: COBIT DS5.19: Malicious software
System: COBIT DS5.20: Firewall control
System: COBIT DS5.2: Authentication and
Access
System: COBIT DS5.4: User Account Changes
System: COBIT DS5.7: Security Surveillance
78-17020-01
Add, Modify, and Delete a Rule Group, page 21-27
Add, Modify, and Delete a Report Group, page 21-30
Display Incidents Related to a Rule Group, page 21-32
Create Query Criteria with Report Groups, page 21-33
Using Rule Groups in Query Criteria, page 21-34
Predefined Rule and Report Groups
Appendix D, "System Rules and Reports."
Corresponding System Rule Groups
System: Access
User Guide for Cisco Security MARS Local Controller
Rule and Report Groups
Table
21-2.
21-25

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents