Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 Administration Manual page 279

Strm administration guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2:
Table of Contents

Advertisement

Table B-10 Default Building Blocks (continued)
Building Block
Default-BB-FalsePositive:
FTP False Positive Events
Default-BB-FalsePositive:
Global False Positive
Events
Default-BB-FalsePositive:
Internal Attacker to
Internal Target False
Positives
Default-BB-FalsePositive:
Internal Attacker to
Remote Target False
Positives
Default-BB-FalsePositive:
LDAP Server False
Positive Categories
Default-BB-FalsePositive:
LDAP Server False
Positive Events
Default-BB-FalsePositive:
Mail Server False Positive
Categories
Default-BB-FalsePositive:
Mail Server False Positive
Events
Default-BB-FalsePositive:
Network Management
Servers Recon
Block
Group
Type
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to include any event
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
STRM Administration Guide
Description
positive QIDs that occur to or from
FTP-based servers that are
defined in the
Default-BB-HostDefinition: FTP
Servers building block.
QIDs that you wish to ignore.
positive QIDs that occur to or from
Local-to-Local (L2L) based
servers.
positive QIDs that occur to or from
Local-to-Remote (L2R) based
servers.
positive categories that occur to or
from LDAP servers that are
defined in the
Default-BB-HostDefinition: LDAP
Servers building block.
positive QIDs that occur to or from
LDAP servers that are defined in
the Default-BB-HostDefinition:
LDAP Servers building block.
positive categories that occur to or
from mail servers that are defined
in the Default-BB-HostDefinition:
Mail Servers building block.
positive QIDs that occur to or from
mail servers that are defined in the
Default-BB-HostDefinition: Mail
Servers building block.
positive categories that occur to or
from network management servers
that are defined in the
Default-BB-HostDefinition:
Network Management Servers
building block.
Default Building Blocks
Associated Building
Blocks, if applicable
Default-BB-HostDefinition:
FTP Servers
Default-BB-HostDefinition:
LDAP Servers
Default-BB-HostDefinition:
LDAP Servers
Default-BB-HostDefinition:
Mail Servers
Default-BB-HostDefinition:
Mail Servers
Default-BB-HostDefinition:
Network Management
Servers
271

Advertisement

Table of Contents
loading

Table of Contents