Wanguard 6.2 User Guide
Configuration » Network & Policy » Response
17
Expiration Delay (seconds)
String
{expiration}
The number of seconds between the last
time the anomaly is detected and the
time the anomaly is expired.
18
Captured Packets
Number
{captured_pkts}
The number of packets captured by the
Response.
19
BGP Log Size (bytes)
Number
{bgplog_bytes}
The size of the BGP announcement log. It
is non-zero if a BGP routing update was
triggered for the anomaly.
20
Unique Dynamic Parameters
String
{exclusive}
Contains dynamic parameter(s) that must
be unique in all active anomalies. It is
usually used for avoiding duplicating
actions across multiple attacks. Example:
set to “{ip} {decoder}” to execute the
action if there is no other active anomaly
towards the same IP and using the same
decoder.
21
Classification [
Unclassified
,
False Positive, Possible Attack,
Trivial Attack, Verified Attack,
Crippling Attack
]
String
{classification}
Console users can manually classify
anomalies in Reports » Tools » Anomalies.
22
Custom Script Return Value
String
The conditional parameter passes only
when the script entered in the Value field
returns 0. The Comparison field must be
set to equal. You can pass Dynamic
Parameters as arguments for the script.
23
String
{software_version}
Wanguard software version.
ANOMALY PARAMETERS
1
Anomaly Description
String
{anomaly}
A description of the anomaly.
2
Anomaly ID
Number
{anomaly_id}
The unique identification number of the
anomaly.
3
Anomaly Comment
String
{comment}
The comment added for the anomaly by
Console users.
4
Direction [
incoming
,
outgoing
] String
{direction}
The direction of the rule that triggered
the anomaly. Can be “incoming” or
“outgoing”.
5
String
{direction_to_from}
It is “to” for incoming anomalies and
“from” for outgoing anomalies.
6
String
{direction_receives_sends}
It is “receives” for incoming anomalies
and “sends” for outgoing anomalies.
7
Domain [
IP
,
subnet
]
String
{domain}
Domain is “IP” when CIDR = 32 for IPv4 or
128 for IPv6; “subnet” in all other cases.
8
Anomaly Class [
threshold
,
profile
]
String
{class}
It is “threshold” for threshold-based
anomalies and “profile” for profiling-
based anomalies.
- 29 -
Summary of Contents for wanguard 6.2
Page 1: ......