High-Level Event
Categories
The high-level event categories include:
Table 2-1 High-Level Event Categories
Category
Description
Recon
Events relating to scanning and other techniques used to identify
network resources, for example, network or host port scans.
DoS
Events relating to Denial of Service (DoS) or Distributed Denial of
Service (DDoS) attacks against services or hosts, for example,
brute force network DoS attacks.
Authentication
Events relating to authentication controls, group, or privilege
change, for example, log in or log out.
Access
Events resulting from an attempt to access network resources,
for example, firewall accept or deny.
Exploit
Events relating to application exploits and buffer overflow
attempts, for example, buffer overflow or web application
exploits.
Malware
Events relating to viruses, trojans, back door attacks, or other
forms of hostile software. This may include a virus, trojan,
malicious software, or spyware.
Suspicious
The nature of the threat is unknown but behavior is suspicious
Activity
including protocol anomalies that potentially indicate evasive
techniques, for example, packet fragmentation or known IDS
evasion techniques.
System
Events related to system changes, software installation, or status
messages.
Policy
Events regarding corporate policy violations or misuse.
CRE
Events generated from an offense or event rule. For more
information on creating custom rules, see the STRM
Administration Guide.
Potential Exploit
Events relating to potential application exploits and buffer
overflow attempts.
SIM Audit
Events relating to user interaction with the Console and STRM
Administration Console.
VIS Host
Events relating to the host, ports, or vulnerabilities that the VIS
Discovery
component discovers.
Application
Events relating to application activity.
STRM Event Category Correlation Reference
About Event Category Correlation
3
Need help?
Do you have a question about the SECURITY THREAT RESPONSE MANAGER 2008.2 - EVENT CATEGORY CORRELATION REFERENCE GUIDE REV 1 and is the answer not in the manual?
Questions and answers