• No results found

Extreme Security asset profile data does not display obfuscated data after upgrade

19 Event categories

High-level event categories Recon DoS Authentication Access Exploit Malware Suspicious Activity System Policy Unknown CRE Potential Exploit User Defined SIM Audit

VIS Host Discovery Application

Audit Risk

Risk Manager Audit Control

Asset Profiler

Event categories are used to group incoming events for processing by Extreme Networks Security Analytics. The event categories are searchable and help you monitor your network.

Events that occur on your network are aggregated into high-level and low-level categories. Each high- level category contains low-level categories and an associated severity level. You can review the severity levels that are assigned to events and adjust them to suit your corporate policy needs.

High-level event categories

Events in Extreme Security log sources are grouped into high-level categories. Each event is assigned to a specific high-level category.

Categorizing the incoming events ensures that you can easily search the data.. The following table describes the high-level event categories.

Table 87: High-level event categories

Category Description

Recon on page 195 Events that are related to scanning and other techniques that are used to identify network resources, for example, network or host port scans. DoS on page 196 Events that are related to denial-of-service (DoS) or distributed denial-of-

service (DDoS) attacks against services or hosts, for example, brute force network DoS attacks.

Authentication on page 199 Events that are related to authentication controls, group, or privilege change, for example, log in or log out.

Access on page 203 Events resulting from an attempt to access network resources, for example, firewall accept or deny.

Exploit on page 205 Events that are related to application exploits and buffer overflow attempts, for example, buffer overflow or web application exploits.

Malware on page 206 Events that are related to viruses, trojans, back door attacks, or other forms of hostile software. Malware events might include a virus, trojan, malicious software, or spyware.

Suspicious Activity on page 207 The nature of the threat is unknown but behavior is suspicious. The threat might include protocol anomalies that potentially indicate evasive techniques, for example, packet fragmentation or known intrusion detection system (IDS) evasion techniques.

System on page 209 Events that are related to system changes, software installation, or status messages.

Policy on page 212 Events regarding corporate policy violations or misuse. Unknown on page 213 Events that are related to unknown activity on your system. CRE on page 214 Events that are generated from an event rule.

Potential Exploit on page 214 Events relate to potential application exploits and buffer overflow attempts. User Defined on page 215 Events that are related to user-defined objects.

SIM Audit on page 216 Events that are related to user interaction with the Console and administrative functions.

Application on page 218 Events that are related to application activity. Audit on page 232 Events that are related to audit activity.

Control on page 234 Events that are related to your hardware system. Asset Profiler on page 236 Events that are related to asset profiles.

Recon

The Recon category contains events that are related to scanning and other techniques that are used to identify network resources.

The following table describes the low-level event categories and associated severity levels for the Recon category.

Table 88: Low-level categories and severity levels for the Recon events category Low-level event category Description Severity level (0 - 10) Unknown Form of Recon An unknown form of reconnaissance. 2

Application Query Reconnaissance to applications on your system. 3 Host Query Reconnaissance to a host in your network. 3

Network Sweep Reconnaissance on your network. 4

Mail Reconnaissance Reconnaissance on your mail system. 3 Windows™ Reconnaissance Reconnaissance for Windows operating system. 3

Portmap / RPC r\Request Reconnaissance on your portmap or RPC request. 3 Host Port Scan Indicates that a scan occurred on the host ports. 4 RPC Dump Indicates that Remote Procedure Call (RPC) information is

removed.

3 DNS Reconnaissance Reconnaissance on the DNS server. 3 Misc Reconnaissance Event Miscellaneous reconnaissance event. 2 Web Reconnaissance Web reconnaissance on your network. 3 Database Reconnaissance Database reconnaissance on your network. 3 ICMP Reconnaissance Reconnaissance on ICMP traffic. 3 UDP Reconnaissance Reconnaissance on UDP traffic. 3 SNMP Reconnaissance Reconnaissance on SNMP traffic. 3

ICMP Host Query Indicates an ICMP host query. 3

UDP Host Query Indicates a UDP host query. 3

NMAP Reconnaissance Indicates NMAP reconnaissance. 3 TCP Reconnaissance Indicates TCP reconnaissance on your network. 3 UNIX Reconnaissance Reconnaissance on your UNIX™ network. 3

FTP Reconnaissance Indicates FTP reconnaissance. 3

DoS

The DoS category contains events that are related to denial-of-service (DoS) attacks against services or hosts.

The following table describes the low-level event categories and associated severity levels for the DoS category.

Table 89: Low-level categories and severity levels for the DoS events category

Low-level event category Description Severity level (0 -

10) Unknown DoS Attack Indicates an unknown DoS attack. 8

ICMP DoS Indicates an ICMP DoS attack. 9

Table 89: Low-level categories and severity levels for the DoS events category (continued)

Low-level event category Description Severity level (0 -

10)

TCP DoS Indicates a TCP DoS attack. 9

UDP DoS Indicates a UDP DoS attack. 9

DNS Service DoS Indicates a DNS service DoS attack. 8 Web Service DoS Indicates a web service DoS attack. 8 Mail Service DoS Indicates a mail server DoS attack. 8 Distributed DoS Indicates a distributed DoS attack. 9

Misc DoS Indicates a miscellaneous DoS attack. 8

UNIX™ DoS Indicates a UNIX DoS attack. 8

Windows™ DoS Indicates a Windows DoS attack. 8

Database DoS Indicates a database DoS attack. 8

FTP DoS Indicates an FTP DoS attack. 8

Infrastructure DoS Indicates a DoS attack on the infrastructure. 8

Telnet DoS Indicates a Telnet DoS attack. 8

Brute Force Login Indicates access to your system through unauthorized

methods. 8

High Rate TCP DoS Indicates a high rate TCP DoS attack. 8 High Rate UDP DoS Indicates a high rate UDP DoS attack. 8 High Rate ICMP DoS Indicates a high rate ICMP DoS attack. 8

High Rate DoS Indicates a high rate DoS attack. 8

Medium Rate TCP DoS Indicates a medium rate TCP attack. 8 Medium Rate UDP DoS Indicates a medium rate UDP attack. 8 Medium Rate ICMP DoS Indicates a medium rate ICMP attack. 8 Medium Rate DoS Indicates a medium rate DoS attack. 8 Medium Rate DoS Indicates a medium rate DoS attack. 8 Low Rate TCP DoS Indicates a low rate TCP DoS attack. 8 Low Rate UDP DoS Indicates a low rate UDP DoS attack. 8 Low Rate ICMP DoS Indicates a low rate ICMP DoS attack. 8

Low Rate DoS Indicates a low rate DoS attack. 8

Distributed High Rate TCP DoS Indicates a distributed high rate TCP DoS attack. 8 Distributed High Rate UDP DoS Indicates a distributed high rate UDP DoS attack. 8 Distributed High Rate ICMP DoS Indicates a distributed high rate ICMP DoS attack. 8 Distributed High Rate DoS Indicates a distributed high rate DoS attack. 8 Distributed Medium Rate TCP DoS Indicates a distributed medium rate TCP DoS attack. 8

Table 89: Low-level categories and severity levels for the DoS events category (continued)

Low-level event category Description Severity level (0 -

10) Distributed Medium Rate UDP DoS Indicates a distributed medium rate UDP DoS attack. 8 Distributed Medium Rate ICMP DoS Indicates a distributed medium rate ICMP DoS attack. 8 Distributed Medium Rate DoS Indicates a distributed medium rate DoS attack. 8 Distributed Low Rate TCP DoS Indicates a distributed low rate TCP DoS attack. 8 Distributed Low Rate UDP DoS Indicates a distributed low rate UDP DoS attack. 8 Distributed Low Rate ICMP DoS Indicates a distributed low rate ICMP DoS attack. 8 Distributed Low Rate DoS Indicates a distributed low rate DoS attack. 8 High Rate TCP Scan Indicates a high rate TCP scan. 8 High Rate UDP Scan Indicates a high rate UDP scan. 8 High Rate ICMP Scan Indicates a high rate ICMP scan. 8

High Rate Scan Indicates a high rate scan. 8

Medium Rate TCP Scan Indicates a medium rate TCP scan. 8 Medium Rate UDP Scan Indicates a medium rate UDP scan. 8 Medium Rate ICMP Scan Indicates a medium rate ICMP scan. 8

Medium Rate Scan Indicates a medium rate scan. 8

Low Rate TCP Scan Indicates a low rate TCP scan. 8 Low Rate UDP Scan Indicates a low rate UDP scan. 8 Low Rate ICMP Scan Indicates a low rate ICMP scan. 8

Low Rate Scan Indicates a low rate scan. 8

VoIP DoS Indicates a VoIP DoS attack. 8

Flood Indicates a Flood attack. 8

TCP Flood Indicates a TCP flood attack. 8

UDP Flood Indicates a UDP flood attack. 8

ICMP Flood Indicates an ICMP flood attack. 8

SYN Flood Indicates a SYN flood attack. 8

URG Flood Indicates a flood attack with the urgent (URG) flag on. 8 SYN URG Flood Indicates a SYN flood attack with the urgent (URG) flag

on. 8

SYN FIN Flood Indicates a SYN FIN flood attack. 8

SYN ACK Flood Indicates a SYN ACK flood attack. 8