18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Attack Description<br />

Application<br />

Defense violation<br />

severe<br />

Chapter 19: Auditing and Reporting<br />

Auditing on the <strong>Sidewinder</strong> <strong>G2</strong><br />

Detects when severe attacks violate active policy defined<br />

by Application Defenses, including spam filter reject and<br />

keyword filter reject audits.<br />

DOS all Detects Denial <strong>of</strong> Service attacks <strong>of</strong> all severities. This<br />

attack category also detects all severities <strong>of</strong> TCP SYN<br />

attacks and proxy flood attacks.<br />

DOS severe Detects severe Denial <strong>of</strong> Service attacks. This attack<br />

category also detects TCP SYN attacks and proxy flood<br />

attacks. Severe attacks indicate something is occurring<br />

that an administrator should know.<br />

HA failover Detects when a failover IP address changes because a<br />

High Availability cluster failed over to its secondary/<br />

standby.<br />

IPFilter deny Detects when a connection is denied by the active IP Filter<br />

policy.<br />

IPSEC error Detects when traffic generates IPSEC errors.<br />

TCP SYN attack Detects a possible attempt to overrun the <strong>Sidewinder</strong> <strong>G2</strong><br />

with connection attempts.<br />

Type Enforcement Detects when there is a TE violation due to an<br />

unauthorized user or process attempting to perform an<br />

illegal operation.<br />

VPN Detects VPN audit events.<br />

all audit Detects all attack and system events, regardless <strong>of</strong> type.<br />

attack all Detects attack events <strong>of</strong> all severities. This option also<br />

detects all severities <strong>of</strong> Application Defense violation<br />

attacks, buffer overflow attacks, DOS attacks, general<br />

attacks, policy violation attacks, protocol violation attacks,<br />

and content security violation attacks.<br />

attack severe Detects severe attacks. This option also detects<br />

Application Defense violation attacks, buffer overflow<br />

attacks, general attacks, DOS attacks, policy violation<br />

attacks, protocol violation attacks, and content security<br />

violation attacks. Severe attacks indicate something is<br />

occurring that an administrator should know.<br />

buffer overflow<br />

attack<br />

Detects attempted buffer overflow attacks targeted at<br />

systems protected by the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

config change Detects when the <strong>Sidewinder</strong> <strong>G2</strong>’s configuration changes.<br />

More...<br />

541

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!