Allowing a new sensor implementation to learn

Hi,
I'm setting up a new IPS sensor on an ASA 5500.
I've heard a recommendation that for a new sensor implementation at a given site, it is better to allow the sensor to learn traffic patterns in promiscous mode before deploying inline mode, otherwise the sensor may not interpret certain events correctly.
Is that a valid statement, and if so, does that mean you must wait to deploy any particular policies until this learning is complete?
Thanks.

Let me explain my point of view:
The sensor in question is an AIP-SSM, so the traffic is normalized by the firewall. In this setup there is no difference in the detection capabilities between promiscous and inline. Promiscous mode has problems with traffic that the attacker has fragmented in an abnormal way or modified segments. Both are controlled by the ASA and don't show up at the sensor.
So the signatures will behave the same. Now you want to make sure that you don't lose traffic while you are stil in the phase of minimizing or eliminating your false polsitives. You could filter out the deny-actions, but as a human you could make a mistake there and you configure something that has to be reconfigured later when your first tuning-phase is over. Both is not a problem when you observe your sensor in promiscous-mode. The change to inline is then very easy and your sensor doesn't need to be changed any more.
For your promiscous delta: The PD has nothing to do how or if a signature triggers or how the signature behaves. It is only a modifier for your Risk-Rating that helps you to make better decisions when you are at your monitoring-console, have thousands of alarms and have to decide which to process first.
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Similar Messages

  • How to register new interface implementation?

    Hi,
    I have the following problem:
    There exists a self written webdynpro application. This application uses a Java Interface. The administrator of the application can add new functionality to the application by adding a new line to a table. He inserts the name of a class which implements that Java interface. This class has the new functionality.
    For each interface implementation the user of the webdynpro gets a value into a list. He can select an entry from this list. This value tells to the application that it has to create an object from the related java interface implementation.
    Now I wonder how I can tell to the webdynpro application that it knows all interface implementations which will come in the future? If I do not "register" or reference the new interface implementations, then I think the webdynpro application has ClassNotFound errors.
    The developers should make there own projects for each interface implementation an deploy them. But what must be done, that the webdynpro application knows them?
    Can you please give me some suggestions?
    Thank you and best regards,
    Marcus

    You can register a Mac, but not an accessory like the Time Capsule. Keep a copy of your sales receipt.....just in case.

  • New GL implementation impact

    Dear All
    We are going to implement New GL in our ECC system .
    In our existing system landscape we have profit center and GL reporting based on extractors 0EC_PCA_1& 0EC_PCA_2
    My question is if post New GL implementation we can still use the existing extractors or we need to switch to new extractors to maintain the current
    reporting in BW ?
    Thanks
    Ankush

    Suyash
    You are correct . I did some more analysis on my side and 0EC_PCA_1& 0EC_PCA_2 are fetching data from GLPCA /GLPCT tables which will become obsolete after new GL implementation . So we would need to use one of the below extractos to replace the existing ones ( PCA extractors )
    0FI_GL_10
    0FI_GL_14
    Regards
    Ankush

  • Hi all new here, am just learning and when i activate the dodge or burn symbol i click over the area to be worked and my Mac freezes. only in the elements software. if i go out of  elements i cannot get back in and have to force a software close, any sugg

    Hi all new here, am just learning and when i activate the dodge or burn symbol i click over the area to be worked and my Mac freezes. only in the elements software. if i go out of  elements i cannot get back in and have to force a software close, any suggestions and please help

    Please post Photoshop Elements related queries over at
    http://forums.adobe.com/community/photoshop_elements

  • How do i authorize my itunes to allow my new surface to  play my existing playlists

    how do i authorizen my itunes to allow my new surface to play my existing playlist

    Authorization
    iTunes Store- Authorize or deauthorize your Mac or PC.
    In iTunes you use the Authorize This Computer or De-authorize This Computer option under the Store menu in iTunes' menubar. For Windows use the ALT-S keys to access it. Or turn on Windows 7 and 8 iTunes menus: iTunes- Turning on iTunes menus in Windows 8 and 7.

  • New to Implementation

    Hi Experts,
    I new to implementation project. Project is ready to start here the existing no system for client. We have to build the SAP BI system to them. R/3 is in process BI is going to start. Can Please any body guide me What are the reports  we have to show in demo to them based on that we have to gather the requirement from them. we have SD,FI,MM,QM,PM,PP,HR modules to implement.
    Please guide me....

    Hi,
    Check the below link which provides all the business content info like , IOs, ICs, DSOs, Data sources used and the standard Bi content reports...
    http://help.sap.com/saphelp_nw70ehp2/helpdata/en/6a/f247bf0ce745eab5648a309fbd784e/frameset.htm
    Here in the link you have BI Content -click on it - here it will displays all the BI content related all modules...
    [sales N Distribution|http://help.sap.com/saphelp_tm80/helpdata/en/f0/3baf6718d2427a94ced005f298be06/frameset.htm]
    Condition Rate Deviation (Sales Order and Billing Document)
    Condition Amount (Billing Document Document: Condition Amount (Sales Order)] Condition Amount (Sales Order)
    Document: Condition Amount By Customer] Condition Amount By Customer
    Document: Average Delivery Processing Times] Average Delivery Processing Times
    Document: Billing Documents] Billing Documents
    Document: Deliveries] Deliveries
    Document: Delivery Delays per Sales Area] Delivery Delays per Sales Area
    Document: Delivery Delays per Sold-to Party] Delivery Delays per Sold-to Party
    Document: Distribution Channel Analysis] Distribution Channel Analysis
    Document: Faultless Sales Order Processing] Faultless Sales Order Processing
    Document: Fulfillment Rates] Fulfillment Rates
    Document: Fulfillment Rates: Values] Fulfillment Rates: Values
    Check the below links for FI
    http://help.sap.com/saphelp_nw70ehp2/helpdata/en/65/7beb3cad744026e10000000a11405a/frameset.htm
    General Ledger
    http://help.sap.com/saphelp_nw70ehp2/helpdata/en/57/dd153c4eb5d82ce10000000a114084/frameset.htm
    [Asset Accounting|http://help.sap.com/saphelp_bic735/helpdata/en/a8/f4153c4eb5d82ce10000000a114084/frameset.htm]
    Etc
    All HR related
    help.sap.com/saphelp_nw70ehp2/helpdata/en/2a/77eb3cad744026e10000000a11405a/frameset.htm

  • I-tunes is note letting me access i-tunes store without first dowloading the new version of i-tunes. The problem is that my older operating system won't work and is not allowing the newer i-tune versions to work.  How can I just get use the old i-tunes?

    I-tunes is note letting me access i-tunes store without first dowloading the new version of i-tunes. The problem is that my older operating system won't work and is not allowing the newer i-tune versions to work.  How can I just get use the old i-tunes?

    Hi,
    Not sure if any of you above have managed to solve your problem or not but after coming across this same problem myself today as I am currently 'sofa bound' I decided to make it my mission to find a way around it.
    Initially I did think, having ready what seemed like a million questions and people with the same problem, that the only way was to buy OS X 10.5 ... HOWEVER, no. In among all these threads I found a jewel - Download I Tunes 9.2.1 which gets rid of the download itunes 10 advert and allows you to then buy from itunes again :-)  I am now one very happy lady.
    I apologise to all those that dont have older versions of OS X that maybe wont support even this upgrade but certainly for those like me with just 4yr old lap tops at least it means it not longer means buying a new one.
    Hope this helps son very frustrated people like myself - so much for apple support!

  • I upgraded from a I phone 4 to 5s. I purchased an adapter to allow the new phone to connect to my Sony dock. I cannot connect and all I get is a message saying the phone does not recognize the device. HELP!!

    I upgraded from an I phone 4 OS7 to a new 5s. I bought an adapter to allow the new phone to connect to my Sony dock. It will charge but it will not play any of my music on the dock. Has anyone else experiencd this and do you know a fix?

    Where did you buy this!? I have a sony docking stAtion that I got for Christmas and my new iphone 5s won't fit into it! So I can't use it! I want something that connects to my iphone 5s that will allow me to plug my phone into my song docking station that has the iphone 4 thing... Is this what you have????

  • So, i changed my apple password. And now when i log into my iMessage it won't allow my new password, or my old one. How do i figure this out?

    Can someone help me with my imessage. I changed my password and now it's not allowing my new password, or my old one.

    Did you purchase Apple Care? If you did, you still have access to Apple Support.  If not, go to your Apple Store and let them help you get it set up correctly.  I'm sure it's something simple we're missing.  Good Luck. 
    Do remember one thing.  iMessage on iPad only works with other iOS devices.  This means you can only text to people who:
    1.  Have an iPhone, iPad, or iPod Touch
    2.  And they have upgraded to iOS 5 or higher

  • HT2928 my phone isn't picking up my brand new sensor

    My iphone 4 isn't picking up my brand new sensor to use with nike+. It wasn't pickinp up my old one and i just assumed that it was time to replace it. I don't know what to do.

    As far as i know, Nike+ on the iPhone doesn't require a sensor. It uses the phone's built in accelerometer.

  • Got gmail with jpg's attached that keep repeating and allows no new messages

    Received a gmail with photo attachments (jpg) that keeps repeating and does not allow any new frontier messages. I have deleted messages, restarted my computer. I do get messages when I go to my frontier.com account.

    Next time you are at the Frontier site either move the problem email out of the inbox and into another folder or delete it so your other messages can get downloaded into Thunderbird.

  • New sensor and calibration

    I have had to get a new sensor. I'm confused on where the calibration info is stored. Will I now have to re-calibrate with the new sensor or is that info stored on the nano from my old sensor? I'm using the same receiver that I had.

    Ok - after a ton of web searching I've now figured out how to fix the multiple sensor problem - add a missed run - and correct bad data.
    Unfortunately I run my itunes on a vista computer - this means that before you delve into the file structure of the ipod you have to discover and run through vista's cryptic new procedure for showing hidden files. Once this is done the only way that seems to work for seeing the new sensor is to delete the old sensor. Using the copy and past you can move these to the folders under the new sensor.
    So much for the idea of having both a nano sensor and the wristband sensor unless you can get them to work with the same sensor - which I haven't succeeded with yet.
    Any ideas on what to do with the fact that the best bluetooth headphones and earbuds either use the sensor jack on the ipod or the nike+ sensor and bluetooth 3.5mm jack won't fit in the same nano at the same time? I have the logitech and jay bird models and both require adaptors to work with t nano.
    I guess the solution will be an ipod that recognizes bluetooth on it's own but then we'll have the headache of figuring out how to get the technologies to work together - it would be nice if this stuff would just work without having to become computer programmers.
    Links
    http://www.walkjogrun.net/blog/index.cfm/2006/9/6/Hacking-the-Sport-Kit
    http://www.walkjogrun.net/blog/index.cfm/2006/9/6/Hacking-the-Sport-Kit

  • Methodology or Process Documents for new XI implementations

    Hi All,
    Can someone point me to any docs on Process/Methodology new XI implementations.
    Thanks & Regards,
    Nandini

    Nandini,
    Please refer the below thread and look for the URL I gave over there
    Re: XI template documents
    Best regards,
    raj.

  • [svn] 1191: ASC side of the new vector implementation .

    Revision: 1191
    Author: [email protected]
    Date: 2008-04-11 07:56:10 -0700 (Fri, 11 Apr 2008)
    Log Message:
    ASC side of the new vector implementation . Strict mode checking now works for all vector types.
    ASC test, tamarin tests, and flex checkintests pass
    Modified Paths:
    flex/sdk/trunk/modules/asc/src/java/macromedia/abc/AbcParser.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/embedding/LintEvaluator.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/embedding/avmplus/ActionBlockConstants .java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/embedding/avmplus/ActionBlockEmitter.j ava
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/embedding/avmplus/ByteCodeFactory.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/embedding/avmplus/GlobalBuilder.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/parser/Evaluator.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/parser/MetaDataEvaluator.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/parser/Node.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/parser/NodeFactory.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/parser/NodePrinter.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/parser/Parser.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/parser/TypeIdentifierNode.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/semantics/CodeGenerator.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/semantics/ConfigurationEvaluator.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/semantics/ConstantEvaluator.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/semantics/Emitter.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/semantics/FlowAnalyzer.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/semantics/QName.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/semantics/ReferenceValue.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/semantics/TypeValue.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/util/Context.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/util/ContextStatics.java
    Added Paths:
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/parser/ApplyTypeExprNode.java
    flex/sdk/trunk/modules/asc/src/java/macromedia/asc/semantics/ParameterizedName.java

    please can you send in yr email address.
    I am attaching the code right now with an explanation!!!

  • Setting up allowance and new account: effect on access to existing library?

    My teenage daughter has been downloading songs from iTunes to her laptop using my iTunes account information (i.e., logging in with my Apple ID and password).
    She has my permission to do that, but she has now asked me to switch her to an iTunes allowance to help her limit her iTunes spending (amen to that).
    1) If the goal is to limit her to the allowance, do I need to assign the allowance to a (new) separate iTunes account -- i.e., create an account for her that she will use from now on, rather than continuing to use my account?
    2) If the answer is, "Yes, you need to create a new account for the allowance," will that limit her ability to access the songs in her existing library on her laptop, all of which were downloaded through my account? Will she have to log out of her account and log into mine to listen to her old music?

    There's an answer to your question but first it's time for a little lecture - if it makes a difference, I don't feel any better about this than you do. ; - )
    I hope you take this unfortunate state of affairs as an opportunity to learn a very important lesson: Back up your iTunes library as soon as you can after resolving this situation because right now you are only one glitch of your iPod away from losing your music entirely.
    Many people come to the Discussions having lost their music in just such situations and, believe me, it's not a happy time for anyone.
    If you place any importance on your playlists and the data they depend on, make sure to include the iTunes Library files in your back-up regimen as well.
    Anyways, that's the lecture. The answer to your problem should be found in Zevoneer's post .
    Good Luck! But once you have the music back on your computer, remember:
    Your music is valuable - please back it up!

Maybe you are looking for

  • Alerts thrown on every retry

    Hi, I've searched and have found previous threads on this issue, but never any resolution. We have a generic alert category defined for all errors that occur in the integration engine and adapter engine. We configured rsxmb_restart_messages to retry

  • Error while fetching variable value from sqlserver database in 11g

    Hi We created a dynamic variable to fetch data from sqlserver database in 11g.But when we test it, it is erroring out as follows: "nqserror: 27024 the execute physical statement must specify a physical sql statement to execute". Please help to overco

  • Idoc in status 12 doesnt reach sap pi

    Hi folks, I have an Idoc2file scenario which is working fine in most cases but occasionnaly a message gets lost: SAP is sending the Idoc to port (goes to stat 03). There is no rfc error, SM58 and table ARFCSSTATE is empty. I run RBDMOIND and status g

  • Workflow Task Error

    Hi,   I am using the ABAP class and method in the workflow task. The task is going under error every time. If i am passing the same data to the funciton module inside the method it works fine. What could be the cause for this? The Task is having no s

  • How to open the pdf file using LabVIEW program

    I want to open the pdf file using the system exe, but it is not happening . Can you help me? Solved! Go to Solution.