Default Building Blocks - Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 Administration Manual

Strm administration guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2:
Table of Contents

Advertisement

266
E
T
NTERPRISE
EMPLATE
Default Building
Blocks
Table B-10 Default Building Blocks
Building Block
Default-BB-Category
Definition: Authentication
Failures
Default-BB-Category
Definition: Authentication
Success
Default-BB-Category
Definition: Authentication
to Disabled Account
Default-BB-Category
Definition: Authentication
to Expired Account
Default-BB-Category
Definition: Authentication
User or Group Added or
Changed
Default-BB-Category
Definition: Countries with
no Remote Access
Default-BB-Category
Definition: Database
Connections
Default-BB-Category
Definition: DDoS Attack
Default-BB-Category
Definition: Exploits,
Backdoors, and Trojans
Default-BB-Category
Definition: Firewall or ACL
Accept
Default-BB-Category
Definition: Firewall or ACL
Denies
D
EFAULTS
Default building blocks for the Enterprise template include:
Block
Group
Type
Category
Event Edit this BB to include all events
Definitions,
Compliance
Category
Event Edit this BB to include all events
Definitions,
Compliance
Category
Event Edit this BB to include all events
Definitions,
Compliance
Category
Event Edit this BB to include all events
Definitions,
Compliance
Category
Event Edit this building block to include
Definitions,
Compliance
Category
Event Edit this BB to include any
Definitions
Category
Event Edit this BB to define successful
Definitions
Category
Event Edit this BB to include all event
Definitions
Category
Event Edit this BB to include all events
Definitions
Category
Event Edit this BB to include all events
Definitions
Category
Event Edit this BB to include all events
Definitions
STRM Administration Guide
Description
that indicate an unsuccessful
attempt to access the network.
that indicate successful attempts
to access the network.
that indicate failed attempts to
access the network using a
disabled account.
that indicate failed attempts to
access the network using an
expired account.
all events that indicate modification
to accounts or groups.
geographic location that typically
would not be allowed remote
access to the enterprise. Once
configured, you can enable the
Default-Rule-Anomaly: Remote
Access from Foreign Country rule.
logins to databases. You may
need to add additional device
types for this BB.
categories that you wish to
categorize as a DDoS attack.
that are typically exploits,
backdoor, or trojans.
that indicate access to the firewall.
that indicate unsuccessful
attempts to access the firewall.
Associated Building
Blocks, if applicable

Advertisement

Table of Contents
loading

Table of Contents