Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 - EVENT CATEGORY CORRELATION REFERENCE GUIDE REV 1 Reference Manual page 19

Event category correlation reference guide
Table of Contents

Advertisement

Table 2-6 Correlation Group 4 Tests (continued)
Traffic Type
Correlation Rules (Tests)
Remote-to-Local
Correlation Group 4 performs the following tests for
Remote-to-Local traffic:
Note: For test details, see
Correlation Group 5
The Correlation Group 5 correlation model provides tests for the following traffic
types:
Table 2-7 Correlation Group 5 Tests
Traffic Type
Correlation Rules (Tests)
Local-to-Local
Correlation Group 5 performs the following tests for
Local-to-Local traffic:
Note: For test details, see
STRM Event Category Correlation Reference
About Event Category Correlation
Relevance of the day of the week
Device credibility
Event rate
Target
Target age
Attacker port
Remote attacker
Geographic location
Time of the attack
Target network
Vulnerable port
Relevance of the day of the week
Device credibility
Event rate
Attacker
Target
Attacker network
Target network
Time of the attack
Table 2-2
.
Table 2-2
.
13

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the SECURITY THREAT RESPONSE MANAGER 2008.2 - EVENT CATEGORY CORRELATION REFERENCE GUIDE REV 1 and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Security threat response manager

Table of Contents