Recon; Dos; Authentication; Access - Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 - EVENT CATEGORY CORRELATION REFERENCE GUIDE REV 1 Reference Manual

Event category correlation reference guide
Table of Contents

Advertisement

High-Level Event
Categories
The high-level event categories include:
Table 2-1 High-Level Event Categories
Category
Description

Recon

Events relating to scanning and other techniques used to identify
network resources, for example, network or host port scans.

DoS

Events relating to Denial of Service (DoS) or Distributed Denial of
Service (DDoS) attacks against services or hosts, for example,
brute force network DoS attacks.

Authentication

Events relating to authentication controls, group, or privilege
change, for example, log in or log out.

Access

Events resulting from an attempt to access network resources,
for example, firewall accept or deny.

Exploit

Events relating to application exploits and buffer overflow
attempts, for example, buffer overflow or web application
exploits.

Malware

Events relating to viruses, trojans, back door attacks, or other
forms of hostile software. This may include a virus, trojan,
malicious software, or spyware.
Suspicious
The nature of the threat is unknown but behavior is suspicious
Activity
including protocol anomalies that potentially indicate evasive
techniques, for example, packet fragmentation or known IDS
evasion techniques.
System
Events related to system changes, software installation, or status
messages.
Policy
Events regarding corporate policy violations or misuse.
CRE
Events generated from an offense or event rule. For more
information on creating custom rules, see the STRM
Administration Guide.
Potential Exploit
Events relating to potential application exploits and buffer
overflow attempts.
SIM Audit
Events relating to user interaction with the Console and STRM
Administration Console.
VIS Host
Events relating to the host, ports, or vulnerabilities that the VIS
Discovery
component discovers.
Application
Events relating to application activity.
STRM Event Category Correlation Reference
About Event Category Correlation
3

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the SECURITY THREAT RESPONSE MANAGER 2008.2 - EVENT CATEGORY CORRELATION REFERENCE GUIDE REV 1 and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Security threat response manager

Table of Contents