| Cisco IPS v6 Risk Ratings |
| Vendor | Cisco |
| Platform | IPS |
| Version | 6 |
| IDS - Cisco |
| Thursday, 16 December 2010 00:44 |
|
The Cisco IPS Sensor generates risk ratings that are assigned to alerts which provides the administrator with an indication to the severity of the alert. There are six values which are used in the calculation of the Risk Rating :
The formula for calculating the Risk Rating is as follows : RR = ASR * TVR * SFR + AAR - PD + WLR Attack severity ratingConfigured on a per signature basis. The ASR indicates how dangerous the detected event is. There are 4 severity levels :
Target Value RatingThe TVR identifies the importance of a network asset through its IP address.
Signature fidelity RatingThe SFR is configured on a per signature basis. This indicates how accurate the signature writer has determined the signature is at detecting the necessary attack. Valid numbers for SFR are 0 to 100. Attack Relevance RatingThe ARR is not configurable. ARR Values are as follows
The AAR allows the system to add relevance to an attack based on the victim’s operating system. Such as an IIS attack which would be given a higher AAR if it was being targeted at a Windows server rather than if it was targeted towards an Apache server. Promiscuous DeltaThe PD is only relevant when the IPS sensor is operating within promiscuous mode. If the sensor is inline the PD is subtracted from the Risk Rating. The PD lowers the risk rating of certain alerts when functioning within promiscuous mode. Watch List RatingThe WLR is derived from the watch list within the Cisco Works Management Center for CSA. The watch list is a list of IP's that is has determined eligible for quarantine. If the attacked of alerts is found on the watch list the WLR for that attacker is added to the rating. |
Latest Articles
- F5 LTM VE 10.2.x - Interfaces not recognised
- Cisco ASA - Security Levels / NAT Control
- F5 LTM - OneConnect
- Django - CSRF verification failed. Request aborted.
- F5 LTM VE - Unable to attach to PCI device 02:01.00 for Interface 1.1
- F5 LTM - Connection Management
- Brocade ADX - FTP
- PKI - Chain of Trust
- Juniper SRX - Site to Site VPN using a Dynamic IP address
- F5 LTM - How do I perform software installations ?
- Juniper SRX - NAT
- Juniper SRX - How to configure a route based VPN
- Juniper SRX - Dynamic VPN
- Juniper SRX - How to configure a policy based VPN
- Brocade ADX - NAT
- Brocade ADX - CSW nested rules
- How do I upgrade a Juniper SRX Series gateway
- Cisco ASA - How do I capture ARP`s ?
- Juniper SRX - Configuring Source NAT with pool
- Running a packet capture on a Juniper SRX
Popular
- Proxy ARP – SPLAT
- Check Point Commands
- IPSO - Commands
- ASA 8.3 - How to configure NAT
- vSphere - Creating User and Group Permissions
- PEMU - Free Cisco PIX Firewall Emulator / Simulator
- Configuring Wireless Connectivity within Backtrack 4 r2
- Juniper Netscreen Commands
- Juniper Netscreen - NAT Explained
- How do I install snmpwalk / snmpget using Yum ?
- Netscreen - NSRP
- ESX Convertor - The session is not authenticated
- Troubleshooting a Netscreen Site 2 Site VPN
- ESX - ViClient Cannot connect to host
- Endpoint Connect Installation / Troubleshooting Guide
- Check Point - How to Reset SIC
- ESXi - Connecting to a named pipe
- Netscreen - Routing Basics / Virtual Routers / PBR
- Check Point Logging Troubleshooting Guide
- Configuring Windows 2008 R2 as an NTP Server
