Preface: Configuration parametersLogo -Internet Security Systems

Configuration parameters

advICE :Intrusions : Config
 FAQ
Oh my gosh, I'm being HACKED!!!
How do I report the hacker to my ISP?
I'm seeing lots of attacks, is this normal?
Summary Most of the configuration parameters are documented under the intrusion detection to which they apply. Global parameters which affect the overall operation of the product are defined here.

Details

The syntax of a parameter in the configuration file is parameter=value. For example, to specify that FTP analysis be done on port 99, use the command tcpport.FTP=99. The default value of each parameter is given in the second column of the configuration table.

The trust parameters can be used to eliminate reports of incidents which occur as part of your normal network operation. For example, if you use the network to backup your system every night, you might want to trust the backup system as an intruder, because it is likely to trigger several file-access intrusions when it accesses sensitive files.

 configuration for this item
tcpport.FTP21The port on which FTP analysis is done. Several ports can be specified by including a different tcpport configuration line for each port
tcpport.TELNET23The port on which TELNET analysis is done.
tcpport.SMTP25The port on which SMTP analysis is done.
tcpport.DNS53The port on which DNS analysis is done.
tcpport.FINGER79The port on which FINGER analysis is done.
tcpport.HTTP80The port on which HTTP analysis is done.
tcpport.POP3110The port on which POP3 analysis is done.
tcpport.IDENT113The port on which IDENT analysis is done.
tcpport.MSRPC135The port on which MSRPC analysis is done.
tcpport.NETBIOS139The port on which NETBIOS analysis is done.
tcpport.IMAP4143The port on which IMAP4 analysis is done.
tcpport.RLOGIN513The port on which RLOGIN analysis is done.
tcpport.SQL2025 and 1433The port on which SQL analysis is done.
tcpport.SOCKS1080The port on which SQL analysis is done.
tcpport.IRC7777 and 8888The port on which IRC analysis is done.
irc.low16660An additional minimum port on which IRC analysis is done.
irc.high16669An additional maximum port on which IRC analysis is done.
irc.low17000An additional minimum port on which IRC analysis is done.
irc.high17002An additional maximum port on which IRC analysis is done.
http.heuristiconA heuristic is used to determine whether HHTP traffic is being used on a port other than port 80. To disable this heuristic, specify a value of off for this parameter.
ip.checksumonSpecify off to disable the IP checksum calculation.
tcp.checksumonSpecify off to disable the TCP checksum calculation.
udp.checksumonSpecify off to disable the UDP checksum calculation.
trust.addressnoneA list of intruder IP addresses which are not to be reported.
trust.issuenoneA list of issues which are not to be reported.
trust.pairnoneA list of IP address,issue pairs which are not to be reported. For example, to trust issue 2002701 from 192.68.0.1, use the command trust.pair=192.68.0.1,2002701.

 
Version appeared:  

Privacy Policy |  Copyright Info