Download Cabletron Systems ETWMIM Specifications

Transcript
Automated Security Manager Help
Dragon has four default notification rules: netsight−atlas−asm−attacks, netsight−atlas−asm−compromise,
netsight−atlas−asm−informational, and netsight−atlas−asm−misuse. Each of Dragon's notification rules has a
corresponding event category in ASM: ASM_ATTACKS, ASM_COMPROMISE,
ASM_INFORMATIONAL, and ASM_MISUSE.
For ASM's response to a serious threat to be timely and effective, it is important that ASM only be notified of
serious threats. The following table lists the Dragon events for which notification to ASM is recommended:
BACKDOOR:PHATBOT
COMP:MS−DIR
COMP:ROOT−ICMP
COMP:ROOT−TCP
COMP:ROOT−UDP
COMP:SDBOT−LOGIN
COMP:SDBOT−NETINFO
COMP:SPYBOT−DOWNLOAD COMP:SPYBOT−INFO
COMP:SPYBOT−KEYLOG
COMP:WIN−2000
COMP:WIN−XP
GENERIC:UPX−EXE
MS−BACKDOOR
MS−BACKDOOR2
Event Categories
98