DefensePro User Guide
Security Configuration
Document ID: RDWR-DP-V0602_UG1201
123
Footprint Strictness
When DefensePro detects a new attack, the Behavioral DoS module
generates an attack footprint to block the attack traffic. If DefensePro
is unable to generate a footprint that meets the footprint-strictness
condition, the device issues a notification for the attack but does not
block it. The higher the strictness, the more accurate the footprint.
However, higher strictness increases the probability that the device
cannot generate a footprint.
Values:
•
High—Enforces at least three Boolean ANDs and no other
Boolean OR value in the footprint. This level lowers the
probability for false positives but increases the probability for
false negatives.
•
Medium—Enforces at least two Boolean ANDs and no more than
two additional Boolean OR values in the footprint.
•
Low—Allows any footprint suggested by the Behavioral DoS
module. This level achieves the best attack blocking, but
increases the probability of false positives.
Note:
Footprint Strictness Examples, page 124
footprint strictness requirements.
Advanced Parameters
These settings affect periodic attack behavior. The settings are used to effectively detect and block
these attack types.
Duration of Non-attack
Traffic in Analysis State
The time, in seconds, at which the degree of attack falls below and
stays below the hard-coded threshold in the Analysis state. When the
time elapses, DefensePro declares the attack to be terminated.
Values:
•
0—DefensePro declares the attack to be terminated
immediately.
•
1–30
Default: 0
Duration of Non-attack
Traffic in Blocking State
The time, in seconds, at which the degree of attack falls below and
stays below the hard-coded threshold in the Blocking state. When the
time elapses, DefensePro declares the attack to be terminated.
Values:
•
0—DefensePro declares the attack to be terminated
immediately.
•
1–300
Default: 10
Note:
There is no typical use case for reducing the value from the
default.
Table 56: BDoS Protection Global Parameters
Parameter
Description
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...