Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 Administration Manual page 352

Strm administration guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2:
Table of Contents

Advertisement

344
ISP T
D
EMPLATE
EFAULTS
Table D-9 Default Rules (continued)
Rule
Default-Rule-Recon:
Remote Database
Scanner
Default-Rule-Recon:
Remote DHCP
Scanner
Default-Rule-Recon:
Remote FTP Scanner
Default-Rule-Recon:
Remote Game Server
Scanner
Default-Rule-Recon:
Remote ICMP
Scanner
Default-Rule-Recon:
Local IM Server
Scanner
Default-Rule-Recon:
Local IRC Server
Scanner
Default-Rule-Recon:
Remote LDAP Server
Scanner
Default-Rule-Recon:
Remote Mail Server
Scanner
Default-Rule-Recon:
Remote P2P Server
Scanner
STRM Administration Guide
Rule
Type
Enabled Description
Event
True
Reports a scan from a remote host
against other local or remote targets. At
least 30 hosts were scanned in 10
minutes.
Event
True
Reports a remote host attempting
reconnaissance or suspicious
connections on common DHCP ports to
more than 30 hosts in 10 minutes.
Event
True
Reports a remote host attempting
reconnaissance or suspicious
connections on common FTP ports to
more than 30 hosts in 10 minutes.
Event
True
Reports a remote host attempting
reconnaissance or suspicious
connections on common game server
ports to more than 30 hosts in 10
minutes.
Event
True
Reports a remote host attempting
reconnaissance or suspicious
connections on common ICMP ports to
more than 60 hosts in 10 minutes.
Event
True
Reports a remote host attempting
reconnaissance or suspicious
connections on common IM server ports
to more than 60 hosts in 10 minutes.
Event
True
Reports a remote host attempting
reconnaissance or suspicious
connections on common IRC server
ports to more than 10 hosts in 10
minutes.
Event
True
Reports a scan from a remote host
against other local or remote targets. At
least 30 hosts were scanned in 10
minutes.
Event
True
Reports a remote host attempting
reconnaissance or suspicious
connections on common mail server
ports to more than 30 hosts in 10
minutes.
Event
True
Reports a remote host attempting
reconnaissance or suspicious
connections on common Peer-to-Peer
(P2P) server ports to more than 60
hosts in 10 minutes.

Advertisement

Table of Contents
loading

Table of Contents