6.x to 7.x Mappings
Table A-1 6.x to 7.0 Keyword Mapping (continued)
6.x Keyword
PSPROTO
PSTRIGGER
PSVERBOSE
RATE
A-36 Keywords/XML Attributes
7.0 XML Attribute
NSC/SC/C/protocol-scan
NSC/SC/C/ProbeDetection/PortRange
NSC/SC/C/verbose
NSC/Heartbeat/rate
Description
Generates
[PROTOCOL-SCAN]
external host probes an internal computer using
multiple protocols. Requires one command line
argument that specifies the protocol threshold.
There are a variety of port scan and port sweep
signatures that exist in normal network traffic.
For example, most web browsers choose a local
source port when connecting to port 80 on the
web server. For every new web request, the web
browser usually increments its local source port.
This can be considered a port scan because it
looks like the web server is connected to the
client on many different ports. One way to
combat this is to tell Network Sensor all of the
target ports that should be monitored for port
scans.
This attribute is used to specify which port
ranges we want Network Sensor to consider.
Ranges of ports may be specified such as 0-
1024. Single ports such as 2049 can also be
specified. Here is an example PSTRIGGER
section from a dragon.net file that records all
ports below 1024, port 2049 for nfs, port 6000 for
X Windows and the upper RPC range for Solaris.
Technical Note
The maximum number of rules is 62.
The new algorithm that is used by
"NSC/SC/C/ProbeDetection/hosts-per-port" on
page A-34 enables the Enterasys IPS Sensor to
specify an ordered list of the information used to
generate an alert. For a port scan, it instructs the
sensor to provide a list of all of the ports that
were probed. In the case of a sweep, all of the IP
addresses that were probed are placed in the
event payload.
Technical Note
This feature is limited to the size of 1500 bytes.
The sensor will include as much of the detail as
possible and leave (...) at the end if the payload
was truncated.
Used to cause "NSC/Heartbeat" on page A-18
messages to occur at intervals shorter than one
hour. rate uses one argument, which specifies
the number of minutes for "NSC/Heartbeat" on
page A-18 messages to occur.
Technical Note
The valid range is 1 to 60.
events when an
Need help?
Do you have a question about the Intrusion Prevention System and is the answer not in the manual?