System - Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 - EVENT CATEGORY CORRELATION REFERENCE GUIDE REV 1 Reference Manual

Event category correlation reference guide
Table of Contents

Advertisement

30
E
C
VENT
ATEGORY

System

Table 2-15 System Categories
Low Level Event
Category
Unknown System
Event
System Boot
System
Configuration
System Halt
System Failure
System Status
System Error
Misc System Event
Service Started
Service Stopped
Service Failure
Successful Registry
Modification
Successful
Host-Policy
Modification
Successful File
Modification
Successful Stack
Modification
Successful
Application
Modification
Successful
Configuration
Modification
Successful Service
Modification
Failed Registry
Modification
C
ORRELATION
The system category indicates that the nature of threat is unknown but the
behavior is suspicious including protocol anomalies potentially indicating evasive
techniques. The associated low-level event categories include:
Description
Indicates an unknown system
event.
Indicates a system boot.
Indicates a change in the
system configuration.
Indicates the system has been
halted.
Indicates a system failure.
Indicates any information event. 1
Indicates a system error.
Indicates a miscellaneous
system event.
Indicates system services have
started.
Indicates system services have
stopped.
Indicates a system failure.
Indicates that a modification to
the registry has been
successful.
Indicates that a modification to
the host policy has been
successful.
Indicates that a modification to a
file has been successful.
Indicates that a modification to
the stack has been successful.
Indicates that a modification to
the application has been
successful.
Indicates that a modification to
the configuration has been
successful.
Indicates that a modification to a
service has been successful.
Indicates that a modification to
the registry has failed.
STRM Event Category Correlation Reference
Severity Level
Event Correlation/
(0 to 10)
Processing
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
6
Correlation Group 5 Scenario 2
Correlation Group 5 Scenario 2
3
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
6
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
1
Correlation Group 5 Scenario 2
Additional Event
Processing

Advertisement

Table of Contents
loading

This manual is also suitable for:

Security threat response manager

Table of Contents