Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 - EVENT CATEGORY CORRELATION REFERENCE GUIDE REV 1 Reference Manual page 11

Event category correlation reference guide
Table of Contents

Advertisement

Table 2-2 Correlation Rules (Tests) (continued)
Rule
Description
Remote Target
Determines if the target network is defined as a remote network
in STRM views.
Geographic
Determines the relative importance of the geographic location of
Location
the target.
Remote attacker
Determines if the attacker network is defined as a remote
network in STRM views.
Attacker IP
Determines if the attacker IP address is included in the list of IP
address
addresses that are highlighted as suspicious in the Remote
Services View.
Attacker port
Determines if the attacker port is included in the list of ports from
which attacks originate as provided by the incidents.org data.
Each low-level event category is processed by one of five event Correlation
Groups. This section provides information on the Correlation Groups including:
Correlation Group 1
Correlation Group 2
Correlation Group 3
Correlation Group 4
Correlation Group 5
STRM Event Category Correlation Reference
About Event Category Correlation
5

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the SECURITY THREAT RESPONSE MANAGER 2008.2 - EVENT CATEGORY CORRELATION REFERENCE GUIDE REV 1 and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Security threat response manager

Table of Contents