‎2010-11-12
03:08 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
IDS and VAM correlation rule
Does anyone have an example of a correlation rule that 1. An IDS alert fires with an attack against a certain Microsoft patch MSxx-xxx. 2. Cross references the VAM data to see if the asset is vulnerable to the IDS attack
or any other IDS and VAM correlation
3 Replies
‎2011-11-14
07:51 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hello - I am in same boat - Please someone guide ?
‎2011-11-14
08:58 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
There is a tutorial for this exact thing in the blogs section of the Intelligence Community. Here is a link to the tutorial: [[page no longer exists]]
‎2011-11-28
12:31 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Watch the video that Matt posted, its pretty good. Essentially all you have to do is apply Confidence Level Filtering in your alert. If you have your VAM properly setup (Foundstone broke in 4.1, so if you use that don't upgrade!!) then envision will correlate the Message ID of the IDS alert to the CVE of your vulnerability. It does this using the internal NIC VID.
