DefensePro User Guide
Real-Time Security Reporting
Document ID: RDWR-DP-V0602_UG1201
277
3. To select the ports for which to display data:
a. Click Select Ports. Data is displayed for ports in the Selected Ports list.
b. Move ports to and from the Selected Ports list, as required.
4. To control the amount of data displayed, change the number of minutes in the Display Last list.
5. To view additional information for a displayed attack:
—
Right-click the corresponding arrowhead in the radar to display summary information for the
attack.
—
Double-click the corresponding arrowhead in the radar to display detailed information for
the attack. For more information, see
Viewing Current Attack Information
When an attack is detected, the DefensePro device creates and reports a security event that
includes the information relevant to the specific attack.
The Current Attacks table displays summary information for current and recent attacks. You can
view additional information for a specific attack, including the attack footprint.
You can view information about a security event, or a group of security events that belong to the
same attack.
You can configure filter settings to display a subset of the current attack data. Filter conditions are
joined by AND, meaning, only attacks that match all the filter conditions are displayed.
To display a summary of current attack information
1. In the Security Monitoring perspective navigation pane, select the DefensePro device or site, for
which to display data.
2. Select the Current Attacks tab.
3. To filter the displayed data, set the filter options as required, and click Go.
Information is displayed in the Current Attacks table for the attacks that match all filter
conditions.
Note:
The attack details contained in the table columns that are hidden by default are
displayed in the Attack Details window for individual attacks.
Table 128: Current Attacks Filter Settings
Parameter
Description
Risk
The severity level of the attack.
Category
The threat type to which the attack belongs—for example, Intrusions, DoS,
Anti-Scanning, and so on.
Rule
The server-protection rule or network-protection rule violated by the attack.
Select Ports
Add the ports for which to display attack data to the Selected Ports list.
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...