Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 Administration Manual page 313

Strm administration guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2:
Table of Contents

Advertisement

Table B-9 Default Rules (continued)
Rule
Default-Rule-Recon:
Local LDAP Server
Scanner
Default-Rule-Recon:
Local Database
Scanner
Default-Rule-Recon:
Local DHCP Scanner
Default-Rule-Recon:
Local DNS Scanner
Default-Rule-Recon:
Local FTP Scanner
Default-Rule-Recon:
Local Game Server
Scanner
Default-Rule-Recon:
Local ICMP Scanner
Default-Rule-Recon:
Local IM Server
Scanner
Default-Rule-Recon:
Local IRC Server
Scanner
Default-Rule-Recon:
Local Mail Server
Scanner
Default-Rule-Recon:
Local P2P Server
Scanner
Rule
Group
Type
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
STRM Administration Guide
Enabled Description
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common LDAP ports to more than 60 hosts in 10
minutes.
True
Reports a scan from a local host against other
local or remote targets. At least 30 host were
scanned in 10 minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common DHCP ports to more than 60 hosts in
10 minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common DNS ports to more than 60 hosts in 10
minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common FTP ports to more than 30 hosts in 10
minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common game server ports to more than 60
hosts in 10 minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common ICMP ports to more than 60 hosts in 10
minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common IM server ports to more than 60 hosts
in 10 minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common IRC server ports to more than 10 hosts
in 10 minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common mail server ports to more than 60 hosts
in 10 minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common Peer-to-Peer (P2P) server ports to
more than 60 hosts in 10 minutes.
Default Rules
305

Advertisement

Table of Contents
loading

Table of Contents