Multi-Thread and Baseline Threshold
Has anybody tried using/creating a correlated rule that uses the baseline threshold and multi-threading on a particular variable (dport, sport, laddr, sadd, etc) in the field? Is this possible to alert on a percentage deviation from a min/hour/day baseline?
Any input would greatly be appreciated?
Hi - has engineering come back with a response on this? - It's been over a month since the initial posting.
Also - This ability is critical to allow customers to use a single alert to baseline multiple variables - thus getting a much greater ROI out of each alert created (@ 64 views per Admin Server).
Thanks for your assistance with this!
In the current implementation of RSA enVision, the event baseline count is generated for the number of events received for a given message (e.g. message id) for a specific period of time. This count generation is independent of a correlation rule and as such the multi-threading capability (e.g. parameterizing the count by message variable) does not apply to this feature.
The capability to generate baselines based upon message variable content has been captured as an enhancement request and will be considered for a future RSA enVision roadmap and release definition.
Baselining on a multi-threaded variable has never worked. I have made multiple requests going back to 2006. It would be nice to be able to do some Anomaly Detection on things like firewalls to look for when port 80, 25, 22, 443, etc. go over x% over the baseline.
The most anoying thing is, that this information is already in IPDB and the only thing RSA has to do is to use it in creative way. They just need to look into "summaries" and allow us to build treshold alerts on summaries tables! In simples possible way: query, field used as a test, treshold conditions and it is it.
Then use this alert into correlation rules .... I know, that there is delay etc, but sampling may be done in 1 minutes slices... For most cases it is enough.