18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 20: IPS Attack and System Event Responses<br />

Creating IPS attack responses<br />

About the Modify Attack Response: Frequency tab<br />

Use this tab to modify the parameters to be met before <strong>Sidewinder</strong> <strong>G2</strong><br />

generates a response. The options are:<br />

• Always respond — Select this option to have <strong>Sidewinder</strong> <strong>G2</strong> respond each<br />

time the attack type specified on the Attack tab occurs.<br />

• Limit responses — Select this option to respond only when the attack<br />

pattern matches the parameters set here:<br />

– Respond if x attacks in y seconds where:<br />

• valid values for x are between 2 and 100000. <strong>Sidewinder</strong> <strong>G2</strong><br />

responds when the x attack occurs.<br />

• valid values for y are between 1 and 100000. This represents a<br />

buffer <strong>of</strong> y seconds, so <strong>Sidewinder</strong> <strong>G2</strong> checks the current time - y.<br />

For example, if you have configured a response to filter for netprobe<br />

attempts, and you want to trigger an attack response if 5 or more<br />

probe attempts occur within a 30-second period, you would enter<br />

“Respond if 5 attacks in 30 seconds.”<br />

– Reset attack count to zero after responding—After x attacks,<br />

<strong>Sidewinder</strong> <strong>G2</strong> zeroes out its attack counter and waits until another x<br />

attacks occur in y seconds before sending out the next e-mail alert or<br />

SNMP trap. If this option is not selected, the same attacks may be used<br />

to generate additional alerts.<br />

About the Modify Attack Response: Response tab<br />

Use this tab to configure how <strong>Sidewinder</strong> <strong>G2</strong> should respond when the attack<br />

type’s pattern matches the criteria on the Frequency tab. The options are:<br />

• Configure an alert — <strong>Sidewinder</strong> <strong>G2</strong> can send an alert using an e-mail, an<br />

SNMP trap, or both.<br />

– Send e-mail: Select this option to send an e-mail to each e-mail address<br />

listed in the Response Settings area. (Access this list from the main IPS<br />

Attack Response window. Additional information is available in<br />

“Configuring the e-mail settings” on page 571.)<br />

– Send SNMP trap: Select this option to send an SNMP trap to the<br />

location(s) configured for the snmpd server. (Configure the SNMP<br />

server at Services Configuration > Servers > snmpd. Additional<br />

information is available in “<strong>Sidewinder</strong> <strong>G2</strong> SNMP traps” on page 579.)<br />

• [Conditional] If configuring an alert, specify how long <strong>Sidewinder</strong> <strong>G2</strong> should<br />

wait before sending the next e-mail or SNMP trap for the same attack type<br />

by using the Wait x seconds between alerts option.<br />

For example, suppose you configure an alert to trigger when 5 or more<br />

probe attempts occur in a 30-second period, and you instruct <strong>Sidewinder</strong><br />

<strong>G2</strong> to wait 300 seconds (five minutes) between alerts.<br />

569

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!