Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 562

Security mars local controller
Table of Contents

Advertisement

List of System Reports
This report recordss user group management events reported by hosts.
Activity: Host User/Group Management - All Events.
Activity: Host User/Group Management - All Events
Activity: Host User/Group Management - Top hosts.
This report ranks hosts by user group management events reported.
Activity: Host User/Group Management - Top hosts.
Activity: Host User/Group Management - Top hosts
Activity: IDS Evasion - Top Event Types.
This report ranks the events that detect an attempt by an attacker to evade detection by Network IDS
systems. This may be web-based obfuscation attacks, fragmentation attacks or TCP/IP based
attacks.
Activity: IDS Evasion - Top Event Types.
Activity: IDS Evasion - Top Event Types
Activity: Inactive Reporting Device - Top Devices.
This report lists devices that are configured to be reporting to CS-MARS bt haven't reported any
event in the last hour.
Activity: Inactive Reporting Device - Top Devices.
This report lists devices that are configured to be reporting to CS-MARS bt haven't reported any
event in the last hour.
Activity: IOS IPS DTM Successful Signature Tuning - All Events.
This report lists all successful IOS IPS signature download activities - both adition and deletion.
CS-MARS Distributed Threat Mitigation (DTM) turns on ACTIVE IPS signatures on IOS routers.
Activity: IOS IPS DTM Successful Signature Tuning - All Events.
This report lists all successful IOS IPS signature download activities - both adition and deletion.
CS-MARS Distributed Threat Mitigation (DTM) turns on ACTIVE IPS signatures on IOS routers.
Activity: IRC - All Events.
This report lists all IRC activities. Typically, worms deposit executables on infected hosts that
initiate IRC connections.
Activity: IRC - All Events.
This report lists all IRC activities. Typically, worms deposit executables on infected hosts that
initiate IRC connections.
Activity: Network Usage - Top Destination Ports By Bytes.
This report ranks the top destination ports by bytes sent and transmitted.
Activity: Network Usage - Top Destination Ports By Bytes.
This report ranks the top destination ports by bytes sent and transmitted.
Activity: Network Usage - Top Destination Ports.
This report ranks destination ports by number of network sessions. This report requires that the
syslog level of routers or firewalls be set to high to be able to capture session events. This report
provides a general usage pattern of the network.
Activity: Network Usage - Top Destination Ports.
User Guide for Cisco Security MARS Local Controller
D-22
Appendix D
System Rules and Reports
78-17020-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents