Symantec 10521146 - Network Security 7120 Administration Manual page 171

Administration guide
Hide thumbs Also See for 10521146 - Network Security 7120:
Table of Contents

Advertisement

Streak Interval
Streak Interval regulates how often the sensor checks traffic for port scans. In
past versions, Streak Interval and Counter Interval were controlled by the same
parameter. Symantec Network Security now provides two parameters that you
can configure independently.
The default is set to 16,383 for optimum sensitivity and performance, and does
not need to be changed under most circumstances. Valid values range from
1,023 to 16,383, inclusive. You can increase sensitivity to port scans by lowering
the value so that the sensor checks more often. Do not make changes to this
parameter without a thorough understanding of how it interacts with
Minimum
Flows,
UDP Minimum
Number of Streak
Packets.
Note: In versions prior to 4.0, Streak Interval and Counter Interval were
controlled by the same parameter. Symantec Network Security now provides
two parameters that you can configure independently.
TCP Minimum Flows
TCP Minimum Flows regulates the number of unacknowledged TCP flows that
the sensor sends to analysis during the time period set by
detects an alarming number of them, it sends the packets to streak analysis,
which inspects the sample of packets and compares IP addresses, ports, and
other characteristics for similarities.
The default is set to 3 for optimum sensitivity and performance, and does not
need to be changed under most circumstances. Valid values range from 3 to
twice the value of the
value will decrease sensitivity. This parameter should not be changed without a
thorough understanding of how it interacts with
Number of Streak
Packets.
UDP Minimum Flows
UDP Minimum Flows regulates the number of unacknowledged UDP flows that
the sensor sends to analysis during the time period set by
detects an alarming number of them, it sends the packets to streak analysis,
which inspects the sample of packets and compares IP addresses, ports, and
other characteristics for similarities.
The default is set to 3 for optimum sensitivity and performance, and does not
need to be changed under most circumstances. Valid values range from 3 to
twice the value of the
Flows,
TCP Number of Streak
TCP Number of Streak Packets
UDP Number of Streak Packets
Configuring sensor detection
TCP
Packets, and
Streak
Interval. If it
parameter. Increasing the
Streak Interval
and
TCP
Streak
Interval. If it
parameter.
Detecting
171
UDP

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security

Table of Contents