18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 19: Auditing and Reporting<br />

Auditing on the <strong>Sidewinder</strong> <strong>G2</strong><br />

542<br />

Attack Description<br />

content security<br />

violation<br />

content security<br />

violation severe<br />

denied<br />

authentication<br />

Detects attacks <strong>of</strong> all severities that are content security<br />

violations. This attack category detects spam, keyword<br />

reject, mime virus change, and mime virus reject attacks.<br />

Detects severe attacks that are content security violations.<br />

This attack category detects spam, keyword reject, mime<br />

virus change, and mime virus reject attacks. Severe<br />

attacks indicate something is occurring that an<br />

administrator should know.<br />

Detects when a user attempts to authenticate and enters<br />

invalid data. For example, if a user is required to enter a<br />

password and entered it incorrectly, the denied auth event<br />

would log the event.<br />

error Detects all system events identified as AUDIT_T_ERROR<br />

in the audit stream.<br />

general attack all Detects general attacks <strong>of</strong> all severities that do not fall into<br />

the pre-defined categories.<br />

general attack<br />

severe<br />

hardware s<strong>of</strong>tware<br />

failure<br />

host license<br />

exceeded<br />

keyword filter<br />

failure<br />

Detects severe general attacks that do not fall into the predefined<br />

categories. Severe attacks indicate something is<br />

occurring that an administrator should know.<br />

Detects when a hardware or s<strong>of</strong>tware component fails.<br />

Detects when the number <strong>of</strong> hosts protected by the<br />

<strong>Sidewinder</strong> <strong>G2</strong> exceeds the number <strong>of</strong> licensed hosts.<br />

Detects when an SMTP mail message is rejected due to a<br />

configured keyword filter.<br />

license expiration Detects when a licensed feature is about to expire.<br />

log overflow Detects when the log partition is close to filling up.<br />

mime virus Detects when a connection is rejected due to the MIME or<br />

Anti-virus policy.<br />

network probe Detects network probe attacks, which occur any time a<br />

user attempts to connect or send a message to a TCP or<br />

UDP port which has no service.<br />

network traffic Detects all connections that successfully pass through the<br />

<strong>Sidewinder</strong> <strong>G2</strong>.<br />

not config change Detects all attack and system events that are not<br />

configuration changes.<br />

More...

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!