DefensePro User Guide
Real-Time Security Reporting
278
Document ID: RDWR-DP-V0602_UG1201
Table 129: Current Attacks Summary Information
Parameter
Description
Start Time
The date and time of the attack start.
Category
The threat type to which this attack belongs—for example, Intrusions, DoS,
Anti Scanning, and so on.
Status
The last-reported status of the attack.
Values:
•
Started—An attack containing more than one security event has been
detected (some attacks contain multiple security events, such as DoS,
Scans, and so on).
•
Occurred (Signature-based attacks)—Each packet matched with
signatures was reported as an attack and dropped.
•
Ongoing—The attack is currently taking place, the time between Started
and Terminated (for attacks that contain multiple security events, such
as DoS, Scans, and so on).
•
Terminated—There are no more packets matching the characteristics of
the attack, and the device reports that the attack has ended.
Risk
The predefined attack severity level.
Values:
•
—High.
•
—Medium.
•
—Low.
•
—Info. Used for very low risk, or when it is not a real attack, but an
event reported to provide additional information.
Attack Name
The name of the detected attack.
Source Address
The source IP address of the attack. If there are multiple IP sources for an
attack, this field displays Multiple. The multiple IP addresses are displayed in
the Attack Details window.
Destination Address The destination IP address of the attack.
Destination L4 Port
The destination port of the attack.
Rule
The name of the configured network-protection policy rule or server-
protection policy rule that was violated by this attack.
To view or edit the rule for a specific attack, right-click the attack entry and
select Go to Rule.
RDW ID
The unique attack identifier issued by device.
Direction
The direction of the attack, inbound or outbound.
Action Type
The reported action against the attack.
Values:
•
Forward—The packet is forwarded to its destination.
•
Drop—The packet is discarded.
•
Reset Source—A TCP Reset packet is sent to the attacker’s source IP
address.
•
Reset Destination—A TCP Reset packet is sent to the attacker’s
destination IP address.
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...