Download Full eXpert-BSM v.1.5 User Manual

Transcript
•
KILL|KILL_ALL <session_id> --- terminate the intrusive session (e.g., kill -9 <session_id>).
•
LOCKOUT <username> --- disable the user account until the
individual responsible for the malicious activity associated with
this account is found.
•
FIXPERMS <filename> --- alter the target file access permissions as specified.
•
FILTER <IP address> --- if a firewall is available, disallow network connectivity from this indicated IP address.
•
CHECKCFG <Host> <Service> --- identifies system
service that appears to have been attacked or has
died.
•
DIAGNOSE <Network Service | Filesystem> --Validate the correct operation of the named network service, or the
availability of the named filesystem.
Line 10: (optional) The primary use of this line is to indicate the relevant user configuration parameters that modify the behavior of the rule that generated this alert.
EMERALD Resolver alerts
The EMERALD resolver alerts are by default written to
$Install/_BSM/results/bsm-alert-{timestamp}.resolver
but could also be sent to another EMERALD components such as the alert collection application efunnel or an analysis engine on a higher level. Resolver alerts can be displayed
by the graphical EMERALD Alert Management Interface described in the following section.
Alert Management Interface
EMERALD provides a unique graphical user interface for managing alerts produced by
EMERALD sensors. Using this interface, you can view individual alerts, manage incident handling reports, print reports, forward reports via email, and view recommendations on responding to attacks. For more information on the Alert Management Interface, refer to the EMERALD Alert Management Interface User’s Guide, Version 1.2
(available in $Install/doc/Emerald-AMI-1-2-manual.pdf).
EMERALD eXpert-BSM User’s Guide
Page 50