18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 19: Auditing and Reporting<br />

Generating reports using the Admin Console<br />

556<br />

Report type Description<br />

root_accesses This report contains a list <strong>of</strong> root access attempts by users who used the srole<br />

command to change roles. This report lists the date that the root access attempts<br />

occurred, the service (srole), the result <strong>of</strong> the attempt, which domain the user tried to<br />

srole to, and who the user was. This report is generated daily.<br />

service_denied This report lists instances when users were denied access to a service because <strong>of</strong> the<br />

restrictions you set up in your active rules (also referred to as the Access Control List, or<br />

ACL). The report lists the source and destination hosts, the user, the service that was<br />

denied, and the total number <strong>of</strong> times a check was made. The meaning <strong>of</strong> these events<br />

depends on several factors, including your site’s security policies. The report could<br />

indicate that an internal user is trying to access an unauthorized system on the Internet.<br />

It might also indicate a service that internal users need, and you may want to consider<br />

making it available.<br />

Note: This report is automatically generated and e-mailed on a daily basis to the<br />

<strong>Sidewinder</strong> <strong>G2</strong> administrator. See “Viewing administrator mail messages on <strong>Sidewinder</strong><br />

<strong>G2</strong>” on page 350 for information on viewing this e-mail.<br />

service_traffic This report lists proxy information on how <strong>of</strong>ten Internet services were used during a<br />

specific period <strong>of</strong> time. You can use this information to gauge how heavily your<br />

<strong>Sidewinder</strong> <strong>G2</strong> is being used.<br />

The report lists each service, the number <strong>of</strong> kB sent to the server, the number <strong>of</strong> kB sent<br />

to the client, the total number <strong>of</strong> kB, and the number <strong>of</strong> connections that were made.<br />

When a service uses a non-standard port (for example, 8000 or 8010), the service’s<br />

port number will also appear in the Service column.<br />

Note: This report is automatically generated and e-mailed on a daily basis to the<br />

<strong>Sidewinder</strong> <strong>G2</strong> administrator. See “Viewing administrator mail messages on <strong>Sidewinder</strong><br />

<strong>G2</strong>” on page 350 for information on viewing this e-mail.<br />

traffic This report lists information about a specific host’s activity while using the system. This<br />

report provides a section for the traffic generated, services denied, and probes<br />

generated by the host that was specified.<br />

udb_action This report, made up <strong>of</strong> two sections, shows the actions performed on the <strong>Sidewinder</strong><br />

<strong>G2</strong>’s user database. One section <strong>of</strong> the report shows the actions performed on the<br />

system components <strong>of</strong> the user database. The other section <strong>of</strong> the report shows the<br />

actions performed on user components <strong>of</strong> the user database.<br />

The user database report lists the date the action occurred, which user it affects, what<br />

action was made to the database (either an addition, a deletion, or a modification), what<br />

type <strong>of</strong> data, or class, received the action, and which administrator changed the data.<br />

user_activity This report lists information about a specific user’s activity on the system. This report<br />

provides a section for the traffic generated, root access attempts, services denied, and<br />

user database actions involving the specified user.<br />

More...

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!