Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 Administration Manual page 315

Strm administration guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2:
Table of Contents

Advertisement

Table B-9 Default Rules (continued)
Rule
Default-Rule-Recon:
Local Windows Server
Scanner
Default-Rule-Recon:
Recon Followed by
Accept
Default-Rule-Recon:
Remote Database
Scanner
Default-Rule-Recon:
Remote DHCP Scanner
Default-Rule-Recon:
Remote DNS Scanner
Default-Rule-Recon:
Remote FTP Scanner
Default-Rule-Recon:
Remote Game Server
Scanner
Default-Rule-Recon:
Remote ICMP Scanner
Default-Rule-Recon:
Local IM Server
Scanner
Default-Rule-Recon:
Local IRC Server
Scanner
Default-Rule-Recon:
Remote LDAP Server
Scanner
Rule
Group
Type
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
STRM Administration Guide
Enabled Description
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common Windows server ports with the same
source IP address more than 5 times, across
more than 200 destination IP address(es) within
20 minutes.
False
Adds an additional event into the event stream
when a host that has been performing
reconnaissance also has a firewall accept
following the reconnaissance activity.
True
Reports a scan from a remote host against other
local or remote targets. At least 30 hosts were
scanned in 10 minutes.
True
Reports a remote host attempting
reconnaissance or suspicious connections on
common DHCP ports to more than 30 hosts in
10 minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common DNS ports to more than 60 hosts in 10
minutes.
True
Reports a remote host attempting
reconnaissance or suspicious connections on
common FTP ports to more than 30 hosts in 10
minutes.
True
Reports a remote host attempting
reconnaissance or suspicious connections on
common game server ports to more than 30
hosts in 10 minutes.
True
Reports a remote host attempting
reconnaissance or suspicious connections on
common ICMP ports to more than 60 hosts in 10
minutes.
True
Reports a remote host attempting
reconnaissance or suspicious connections on
common IM server ports to more than 60 hosts
in 10 minutes.
True
Reports a remote host attempting
reconnaissance or suspicious connections on
common IRC server ports to more than 10 hosts
in 10 minutes.
True
Reports a scan from a remote host against other
local or remote targets. At least 30 hosts were
scanned in 10 minutes.
Default Rules
307

Advertisement

Table of Contents
loading

Table of Contents