Rules

Rules are descriptions of behavior. They are created using queries, which can be simple or complex. For example, a rule could be so simple that it says "show me when this keyword appears in any event," or it could be complex and say "show me all instances of when someone scans one of my networks, and then sometime later attempts to brute-force log in using Secure Shell (SSH) or Telnet, and is successful."

MARS uses rules extensively to identify activities you need to know about. Rules are also used in reports. Figure 1-1 shows one of the built-in rules.

Figure 1-1 Access Web Customer Data Rule

ra

Rule Name:

kfilini Rule: MltL. AUiilit! Allch Web tuilniitr Pill

Statu*:

AClivft

Thii cûiTilMiûri Customer data

ule dotto [Heady c

Ii f!Wl(ti4<jt «tempti to atce Ss customer dita stored by ntwn* lorrjitiYo infomnitiort iuch oj purchasinq hiswi'.

app' c-jtionS, preceded t>. retonneiiiance A ffflds card rmrnberi etc.

Time Range:

ttrtfiti to tfïàt ho«.

0h;3Qm if Miy.

luff* el

Uucu (jiuuri

11* |D#fUlt flllan If

icrvlLc

Name jtvent

Ucvlie Hcuurteil |u»er

Keywurdj Sever

y jluuiil| ) Cluie

Uperallun |

ANY

PenfltrstCi'VieHriloi/DirTraYori^Web,

ANY

ANY ANY

1

fOUOWCD-&Y

ANY

AMY

AMY Hon 9

ANY ANY

J )

OR

i

ANY

AMY

PcnfltTflU/VicHriloi/WobOrdorJnfo

ANY H<jne

ANY" ANY

1

MARS observes a probe or penetration activity, using reconnaissance techniques or directory traversal attacks.

This behavior is followed by the same host attempting to access files referred to as WebOrderInfo, which is a set of files that e-commerce websites typically use for customer data.

Or, if the attempted access of the customer data occurs without previous activities, the rule is still matched.

Continue reading here: False Positives

Was this article helpful?

0 0