18.07.2013 Views

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

Network Security Platform 7.0 IPS Administration Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5<br />

在接口和子接口级别配置策略<br />

<strong>IPS</strong> Sensor 接口节点<br />

当 Sensor 通过默认的启发式检测机制检测出了攻击,即会发出“HTTP:Web Application Server Attack Detected<br />

(HTTP: 检测到 Web 应用程序服务器攻击)”警报(NSP 攻击 ID:0x4029d300)。这被视作是利用漏洞攻击。Threat<br />

Analyzer 的“Alert Details(警报详细信息)”页显示 Sensor 在查询中检测到的任何保留的 SQL 关键字。这些内容会显示<br />

在“Alert Details(警报详细信息)”页中的“SQL Injection Details(SQL 注入详细信息)”部分。<br />

图 5-28 0x4029d300 警报详细信息<br />

320 <strong>McAfee</strong> ® <strong>Network</strong> <strong>Security</strong> <strong>Platform</strong> <strong>7.0</strong> <strong>IPS</strong> 管理手册

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!