Decide what rule types you must configure to accomplish the tasks that you have isolated
Tue, 24 May 2016 | Securing Hosts
When you configure a policy, you are combining multiple rule modules under a common name. That policy name is then attached to a group of hosts, and it uses the rules that make up the policy to control the actions that are allowed and denied on those hosts. You can have several different types of rules in a rule module and, consequently, within one policy. The policy level is the common ground from which host groups acquire the rules that make up their security policy. If you are configuring...
- A dynamic application class is defined by process behavior on a system
- Host Inherits the Policies of Its Groups
- Trojan horse is different from a virus only in that the entire application is written to look like something else when in fact it is an attack tool
- About Application Classes
- Accessing the Csa Mc Interface
- Agent Kits
- Among the most difficult to eliminate completely
- Anatomy of an Attack
- Application Behavior Investigation
- Application Deployment Reports
- Application Layer Attacks
- Buffer Overflow Rule
- Buffer Overflow Rule Cont
- Building Classes as Rule Consequences
- C M
- COM Component Access Control Rules
- Configuration Management
- Configuration Management Recommendations
- Configure an applicationbuilder rule to define your dynamic application class
- Configuring a Data
- Configuring a Rule Using a Dynamic Application Class
- Configuring Groups - 2
- Configuring Product Association
- Configuring Static Application Classes
- Configuring Unknown Product Association
- Correlation
- Course Objectives Cont
- Create New Application Classes from Rule Pages
- CSA Architecture
- CSA Attack Response
- CSA Features
- CSA Features Cont
- CSA Installation Requirements Windows
- CSA Interceptors
- CSA Interceptors Cont
- Csa Mc Button Frame Creating Saving and Deleting Data
- Csa Mc Database Installation
- Csa Mc Installation
- Csa Mc Installation Cont
- Csa Mc Installation Requirements
- Csa Mc Interface
- Data Management
- Data sets
- Data Sets
- Denial of Service Attacks
- Display Only in Show All Mode Option
- Mail Worm Event Correlation
- Escalate their access privileges
- File Event Reports
- Filter Out Duplicates
- General Syslog Rule Configuration Examples
- Generating Reports
- Graphic Symbols
- Hiding the Agent UI
- Host Based Intrusion Protection System
- Importing the Rule Module
- Incomplete
- Installation Applications Policy
- Internal threats
- Internet Information Queries
- IP Spoofing
- Java Script must be enabled
- Kernel Protection Rules Cont
- Legal and Governmental Policy Issues
- Linux
- Localized Language Version Support
- Manage Dynamically Quarantined Files and IP Addresses
- Management Protocol Recommendations
- Maninthe Middle Attacks
- Monitoring the Behavior Analysis
- Need for Network Security
- Network access control
- Network Ethernet
- Network Services Sets Cont
- NTP Many NTP servers on the Internet do not require any authentication of peers
- Number of events
- Objectives - 2 3
- Obtain the Agent kit URL for the group - 2
- Optional Import
- Overview - 2 3 4 5 6 7 8 9
- Packet sniffers
- PolicyManage
- Port Redirection
- Port Scan and Ping Sweep Attack Mitigation
- Preserving Application Process Classes
- Priority 8 Deny - 2
- Protect application registry keys
- Query Tokens
- Reconnaissance Attacks
- Registry Access Control Rules
- Removing Processes from Application Classes
- Removing Processes from Classes
- Report Components
- Restrictive security model Allow required actions and deny all other actions
- Reviewing the Rule Module
- Rule Explanation Page
- Run reports based on group settings
- SAFE Security Architecture
- Scripted uninstall
- Sending Agent Kit URL to Host Cont
- Shell Scripts and Application Classes
- Sniffer and protocol detection
- Sniffer and Protocol Detection Rules
- Start Behavior Analysis
- Start Date and End Date
- Summary - 2
- Summary Cont - 2 3 4 5 6 7 8 9 10 11
- System API Control Rule
- System Correlation Rules
- Task 1 Configure a Data
- Task 1 Configure an Analysis
- Task 1 Create a New Group
- Task 1 Create a Policy
- Task 1 Create a Rule Module
- Task 1 Create a Static Application Class
- Task 1 Install the CSA MC
- Task 1 Launch Attacks Against the CSAProtected Host
- Task 2 Add an Agent Service Control Rule to a Rule Module
- Task 2 Adding a Rule Module to a Policy
- Task 2 Build a New Agent
- Task 2 Configure a File
- Task 2 Create a Dynamic Application Class
- Task 2 Launch Cisco Works and Access the Csa Mc Interface
- Task 2 Start an Analysis
- Task 2 Use Event Log to Analyze Attacks
- Task 3 Add an Application Control Rule to a Rule Module
- Task 3 Change the Group Membership of a Host
- Task 3 Configure a Network Address
- Task 3 Configure an Application Builder Rule
- Task 3 Copying Rules Between Rule Modules
- Task 3 Review a Profiler Report
- Task 3 Verify the Default Servers Group and Obtain the Agent Kit URL
- Task 4 Add a Connection Rate Limit Rule to a Policy
- Task 4 Compare Two Rule Modules
- Task 4 Configure a Network Services
- Task 4 Configure a Rule Using a Dynamic Application Class
- Task 4 Configure Event Sets
- Task 4 Install CSA Software on the Host
- Task 5 Add a Data Access Control Rule to a Rule Module
- Task 5 Configure Alerts
- Task 6 Add a File Access Control Rule to a Rule Module
- Task 6 Configure a COM Component
- Task 6 Filter the Rules Display
- Task 7 Attach a Policy to a Group
- Task 8 Add a Network Access Control Rule to a Rule Module
- Task Configure Event Log Management
- The address that a system is attempting to communicate with
- The application that is accessing the COM component
- The behavior investigation functionality
- The Changing Role of Security
- The Closed Network
- The EBusiness Challenge
- The following are password attack mitigation techniques
- The threat of IP spoofing can be reduced but not eliminated through the following measures
- Threat Capabilities More Dangerous and Easier to
- To penetrate
- To state the ramifications of misuse
- Traffic rate limitingImplementation of traffic rate limiting with the ISP of the network
- Trust Exploitation
- Trust Exploitation Attack Mitigation
- Unprotected Hosts Report
- Use collected data to accurately deploy policies or to generate new policies for unprotected applications using the Cisco Security Agent
- Use HTTPs for communication
- Use IDSs which can scan for known attacks monitor and log attacks and in some cases prevent attacks
- Use intrusion protection effectively
- Use local to indicate all local addresses on the system
- Variable and Application Class Creation
- Viewing Hosts
- Viewing Reports
- Visual Objective - 2
- Visual Objectives - 2 3 4 5
- What Is a Security Policy
- What Should the Security Policy Contain
- Which host you want to select for application analysis
- Working with Reports
- Worm Attack Mitigation
- Worm Attacks
- Worm Virus and Trojan Horse Attacks
- Worms viruses and Trojan horses
