Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT REV 1 Manual page 103

Strm log management users guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT REV 1:
Table of Contents

Advertisement

Table B-6 Default Rules (continued)
Rule
Default-Rule-Recon:
Local Proxy Server
Scanner
Default-Rule-Recon:
Local RPC Server
Scanner
Default-Rule-Recon:
Local Scanner Detected
Default-Rule-Recon:
Local SNMP Scanner
Default-Rule-Recon:
Local SSH Server
Scanner
Default-Rule-Recon:
Local Suspicious Probe
Events Detected
Default-Rule-Recon:
Local TCP Scanner
Default-Rule-Recon:
Local UDP Scanner
Default-Rule-Recon:
Local Web Server
Scanner
Default-Rule-Recon:
Local Windows Server
Scanner
Rule
Group
Type
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
Recon
Event
STRM Log Management Users Guide
Enabled Description
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common proxy server ports to more than 60
hosts in 10 minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common RPC server ports to more than 60
hosts in 10 minutes.
True
Reports a scan from a local host against other
hosts or remote targets. At least 60 hosts were
scanned within 20 minutes. This activity was
using a protocol other than TCP, UDP, or ICMP.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common SNMP ports to more than 60 hosts in
10 minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common SSH ports to more than 30 hosts in 10
minutes.
False
Reports when various suspicious or
reconnaissance events have been detected
from the same local source IP address to more
than 5 destination IP address in 4 minutes. This
can indicate various forms of host probing, such
as Nmap reconnaissance, which attempts to
identify the services and operation systems of
the target.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common TCP ports to more than 60 hosts in 10
minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common UDP ports to more than 60 hosts in 10
minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common local web server ports to more than 60
hosts in 10 minutes.
True
Reports a source IP address attempting
reconnaissance or suspicious connections on
common Windows server ports to more than 60
hosts in 10 minutes.
Default Rules
97

Advertisement

Table of Contents
loading

Table of Contents