Chapter 7 Detecting; About Detection - Symantec 10521146 - Network Security 7120 Administration Manual

Administration guide
Hide thumbs Also See for 10521146 - Network Security 7120:
Table of Contents

Advertisement

Detecting
This chapter includes the following topics:

About detection

In addition to the ability to start detection immediately using protection
policies, Symantec Network Security also provides the tools to fine-tune the
detection to a particular environment using sensor parameters and port
mappings, and to enhance the detection using user-defined signatures.
Symantec Network Security can run multiple detection methods concurrently,
including protocol anomaly detection, signatures, IP traffic rate monitoring, IDS
evasion detection, and IP fragment reassembly.
The Symantec Network Security software and the Symantec Network Security
7100 Series appliance employ a common core architecture that provides
detection, analysis, storage, and response functionality. Most procedures in this
section apply to both the 7100 Series appliance and the Symantec Network
Security 4.0 software. The 7100 Series appliance also provides additional
functionality that is unique to an appliance. Each section describes this
additional functionality in detail.
Symantec Network Security provides a way to tune the sensors to look for
particular types of anomalies and signatures on a port by reconfiguring the
default port mapping, or adding new mappings. For example, mappings can be
added to run services on non-standard ports or to ignore ports on which you
About detection
Configuring sensor detection
Configuring port mapping
Configuring signature detection
Protocol anomaly detection
Chapter
7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security

Table of Contents