18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 20: IPS Attack and System Event Responses<br />

Creating IPS attack responses<br />

566<br />

Figure 229: IPS Attack<br />

Responses: Modify<br />

window<br />

Modifying an IPS attack response<br />

When you modify an IPS attack response, the following window appears.<br />

About the Modify Attack Responses: Attack tab<br />

Use this tab to change this attack response’s attack type. An attack is generally<br />

defined as suspect traffic at either the network or application level. Each attack<br />

type identifies a different attack audit event.<br />

1 Select the attack type for which you want <strong>Sidewinder</strong> <strong>G2</strong> to send out a<br />

response. A complete list is provided in Table 39.<br />

To create additional attack types, see “Configuring new event types” on<br />

page 578.<br />

2 Click OK or the next tab you want to modify.<br />

Note: For descriptions <strong>of</strong> the audit severities, see “Viewing IPS attack and system<br />

event summaries” on page 521.<br />

Table 39: Descriptions <strong>of</strong> pre-defined attacks<br />

Attack Description<br />

ACL deny Detects when a connection is denied by a rule in the active<br />

policy.<br />

Application<br />

Defense violation<br />

all<br />

Detects attacks <strong>of</strong> all severities that violate active policy<br />

defined by Application Defenses. This attack category<br />

includes spam filter attacks and keyword filter failure<br />

attacks.<br />

More...

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!