Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 Administration Manual page 280

Strm administration guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2:
Table of Contents

Advertisement

Table B-10 Default Building Blocks (continued)
Building Block
Default-BB-FalsePositive:
Proxy Server False
Positive Categories
Default-BB-FalsePositive:
Proxy Server False
Positive Events
Default-BB-FalsePositive:
Remote Attacker to
Internal Target False
Positives
Default-BB-FalsePositive:
RPC Server False
Positive Categories
Default-BB-FalsePositive:
RPC Server False
Positive Events
Default-BB-FalsePositive:
SNMP Sender or
Receiver False Positive
Categories
Default-BB-FalsePositive:
SNMP Sender or
Receiver False Positive
Events
Default-BB-FalsePositive:
Source IP and Specific
Event
Default-BB-FalsePositive:
SSH Server False
Positive Categories
Default-BB-FalsePositive:
SSH Server False
Positive Events
Default-BB-FalsePositive:
Syslog Sender False
Positive Categories
Block
Group
Type
Description
False
Event Edit this BB to define all the false
Positive
positive categories that occur to or
from proxy servers that are defined
in the Default-BB-HostDefinition:
Proxy Servers building block.
False
Event Edit this BB to define all the false
Positive
positive QIDs that occur to or from
proxy servers that are defined in
the Default-BB-HostDefinition:
Proxy Servers building block.
False
Event Edit this BB to define all the false
Positive
positive QIDs that occur to or from
Remote-to-Local (R2L) based
servers.
False
Event Edit this BB to define all the false
Positive
positive categories that occur to or
from RPC servers that are defined
in the Default-BB-HostDefinition:
RPC Servers building block.
False
Event Edit this BB to define all the false
Positive
positive QIDs that occur to or from
RPC servers that are defined in
the Default-BB-HostDefinition:
RPC Servers building block.
False
Event Edit this BB to define all the false
Positive
positive categories that occur to or
from SNMP servers that are
defined in the
Default-BB-HostDefinition: SNMP
Servers building block.
False
Event Edit this BB to define all the false
Positive
positive QIDs that occur to or from
SNMP servers that are defined in
the Default-BB-HostDefinition:
SNMP Servers building block.
False
Event Edit this BB to include source IP
Positive
addresses or specific events that
you wish to remove.
False
Event Edit this BB to define all the false
Positive
positive categories that occur to or
from SSH servers that are defined
in the Default-BB-HostDefinition:
SSH Servers building block.
False
Event Edit this BB to define all the false
Positive
positive QIDs that occur to or from
SSH servers that are defined in the
Default-BB-HostDefinition: SSH
Servers building block.
False
Event Edit this BB to define all false
Positive
positive categories that occur to or
from syslog sources.
Associated Building
Blocks, if applicable
Default-BB-HostDefinition:
Proxy Servers
Default-BB-HostDefinition:
Proxy Servers
Default-BB-HostDefinition:
RPC Servers
Default-BB-HostDefinition:
RPC Servers
Default-BB-HostDefinition:
SNMP Servers
Default-BB-HostDefinition:
SNMP Servers
Default-BB-HostDefinition:
SSH Servers
Default-BB-HostDefinition:
SSH Servers
Default-BB-HostDefinition:
Syslog Servers and
Senders

Advertisement

Table of Contents
loading

Table of Contents