Wanguard 6.2 User Guide
Configuration » Network & Policy » Response
9
Threshold Type [
absolute
,
percentage
]
String
{threshold_type}
Threshold-based anomalies can be
defined as “absolute” values or as a
“percentage” of the total traffic received
by Sensor.
10
Anomaly Decoder (Protocol)
[TOTAL,...]
String
{decoder}
The traffic decoder (protocol) for the
detected anomaly.
11
Comparison [
over
,
under
]
String
{operation}
The value is “over” for thresholds
exceeding expectations or “under” for
thresholds below expectations.
12
String
{comparison}
The value is “>” for thresholds exceeding
expectations or “<” for thresholds below
expectations.
13
Unit [
pkts/s
,
bits/s
]
String
{unit}
It is “pkts/s” for packets per second
thresholds or “bits/s” for bits per second
thresholds.
14
Threshold Value
Number*
{rule_value}
The value configured as the threshold.
15
Computed Threshold
Number*
{computed_threshold}
The value of the threshold, dynamically
adjusted for profiling-based and
percentage-based anomalies.
16
Peak Value
Number*
{value}
The highest value of the abnormal traffic.
It represents pkts/s or bits/s, depending
on the anomaly unit.
17
Latest Value
Number*
{latest_value}
The latest value of the abnormal traffic. It
represents pkts/s or bits/s, depending on
the anomaly unit.
18
Sum Value
Number*
{sum_value}
For pkts/s thresholds represents the
number of packets of the abnormal
traffic. For bits/s thresholds it represents
the number of bits of the abnormal
traffic.
19
Peak Rule Severity
Number
{severity}
The ratio between the peak abnormal
traffic rate and the threshold value.
20
Latest Rule Severity
Number
{latest_severity}
The ratio between the latest abnormal
traffic rate and the threshold value.
21
Peak Link Severity
Number
{link_severity}
The ratio between the peak abnormal
traffic rate and the interface's traffic rate.
22
Latest Link Severity
Number
{latest_link_severity}
The ratio between the latest abnormal
traffic rate and the interface's traffic rate.
23
String
{anomaly_log_10}
The first 10 packets or flows of the
abnormal traffic.
24
String
{anomaly_log_50}
The first 50 packets or flows of the
abnormal traffic.
- 30 -
Summary of Contents for wanguard 6.2
Page 1: ......