tailieunhanh - cisco security professional's guide to secure intrusion detection systems phần 4

series 4200 cung cấp nhiều tùy chọn cho các quản trị bảo mật và có thể được nhanh chóng và dễ dàng tích hợp vào các môi trường mạng. Cisco cũng giúp các công ty tận dụng hiện tại chuyển mạch và định tuyến cơ sở hạ tầng thông qua việc sử dụng của Cisco | 178 Chapter 4 Cisco IDS Management Apply Changes button in the upper right-hand corner of the IDM screen. It may take some time but when the changes are complete you will get a success message. Once you have made all of your configuration changes to IDM and your sensors click Logout located next to the Apply Changes button. Using the Cisco Network Security Database The Cisco Network Security Database or NSDB as it is commonly referred to is Cisco s version of a security vulnerability entries in the NSDB correspond with an event or a signature in the IDS. When researching and investigating alarms the NSDB is used to make sense of what is going on within your enterprise. Each IDS Management Console accesses the NSDB in the same manner. In order for you to access the NSDB entry for a signature perform the following steps 1. Access the events in the Event Viewer for IDM or CSPM or drill down to the event in the can either view the live database or a log file. 2. Select the record you want information about. 3. Right-click the record and select NSDB. 4. The NSDB will open in a Web browser with information about the signature in question see Figure . Figure The NSDB Screen Cisco IDS Management Chapter 4 179 If there are related vulnerabilities for a particular signature there will be links to those vulnerabilities. You can view the entire database by clicking the Main link in the left pane. This offers a numerical list of all the signatures currently in the database see Figure . Figure NSDB Main Menu If you are using the Director you have to specify a browser preference to access NSDB. Open nrConfigure select Preferences from the File menu and enter the path to the browser then click OK. 180 Chapter 4 Cisco IDS Management Summary As you can see there is a ton of information to absorb regarding management of sensors. Instead of a single method Cisco presents three different ways to get the job