Global correlation / reputation filtering in monitoring mode

We use Cisco appliances primarily in monitoring mode.  We'd like to use the IPS reputation filtering / global correlation to alert us when we have connections to "bad" IP addresses (e.g. botnet, etc).  Is it even possible to use either of these features for this purpose?  According the the following document is appears there may not be alerts for packets denied before signature analysis.  Surely that can't be???
http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_collaboration.html#wp1067283
"Note This feature only applies to global correlation inspection where the traffic is allowed if no specific signature is matched. It does not apply to reputation filtering where the packet is denied before signature analysis, and no alerts are generated when packets are denied by reputation filtering. "

Just listened to the techtalk on global correlation. about 16 minutes in...."we do not send events just to keep the load quiet".   Can someone from Cisco please confirm that this completely naive and poorly engineered facet of the solution still works this way? I'm sorry to sound like an arse, but I am so completely frustrated with the value we get out of these appliances.  Apparently, the ASA botnet functionality can do what we want, but not the stand alone IPS appliance....come on Cisco.

Similar Messages

  • MARS 6.0.4 reporting for IPS 7.0 Global Correlation Reputation Filtering

    Does anyone know if there is a report available in MARS to see what IP addresses were denied by Reputation Filtering on IPS 7.0?
    I found a report that shows attacks that were prevented due to global correlation score, but not for packets denied by Reputation Filtering.
    Replies are greatly appreciated.
    Thanks,
    Mark

    Thanks for the reply, but what I am looking for is reporting on what packets were dropped with Reputation Filtering(doesn't have a report in MARS) Not the GLobal Correlation risk rating blocks(Which does have a report available in MARS).

  • Global Correlation Risk Delta

    Hi,
    I'm currently working on Tuning a pair of IPS modules in ASA's. We are currently in Promiscous and tuning/filtering to ensure we don't block any valid traffic when making the switch to inline.
    We are using the new 7.0.1 code and getting the global correlation / reputation data - works great & rocks.
    When viewing the events - there is a paramater - "Global Correlation Risk Delta" -- Could someone explain to me what that is?
    I understand how it adjusts the RR based on reputation & have the chart (including it for those who do not have it - got it from a networkers prezo). However I am having a hard time figuring out what Global Correlation Risk Delta is/means/does...anyone know?
    Thanks,
    Brad

    Here is a basic description.
    Without Global Correlation (versions prior to 7.0, or version 7.0 with the feature turned off) all alert triggerings will have a Risk Rating calculated.
    How a Risk Rating is calculated is explained in the following White Paper on cisco.com:
    http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/prod_white_paper0900aecd806e7299.html
    Now with version 7.0 when Global Correlation is enabled there is now a new parameter added to the Risk Rating calculation ( + Global Correlation Risk Delta )
    The Global Correlation Risk Delta is either 0 or a positive value and so can keep the Risk Rating the same, or raise the Risk Rating, but will not decrease the Risk Rating.
    The Global Correlation Risk Delta is calculated based on both the Attacker IP address, and the Initial Risk Rating ( The Initial Risk Rating is the Risk Rating calculated without the Global Correlation Risk Delta).
    When Global Correlation is enabled in version 7.0 the sensor will download a Reputation Database from the cisco servers. This reputation database contains lists of Public IP Addresses that have been known to be sources of attacks in the past. With that database a Negative Reputation Score is determined for each Address in the database. The Negative Reputation Score could range anywhere from a -0.5 to a -10. If only a few atttacks have been seen from the address, the score may be only slightl negative in the -0.5 - -3 range. The worst offending Attacker IP Addresses could have negative scores in the -8 to -10 range.
    That Reputation Database is only for Public IP Addresses. So Private IP Addresses (addresses used only with NAT/PAT and are not Internet routable) will not exist in the Reputation Database.
    If the attacker IP Address is a Private IP Address, or is a Public IP Address that is NOT in the Reputation Database, then the sensor will automatically set the Global Correlation Risk Delta to 0.
    When added into the Original Risk Rating, the Risk Rating winds up the same (no change).
    So Global Correlation has no effect on Private IP Addresses, or Public IP Addresses that do NOT have Negative Reputation.
    It is only when the Attacker is from a Public IP Address with Negative Reputation that the Global Correlation Risk Delta is calculated.
    Internally the sensor has a formula to calculate what that Delta should be.
    The inputs to that formula are the Negative Reputation Score for the Atttacker IP, Original Risk Rating, as well as some proprietary variables for fine tuning the formula.
    All of these are inputs to the formula, and the one output is the Delta.
    The Delta is then Added to the Initial Risk Rating and results in a Higher Risk Rating.
    The chart from your first post is a result of plugging in the highest 20 possible Risk Ratings, and 20 possible negative Reputation scores, and uses the original proprietary variable settings, and shows you what the formula will output as the Global Correlation Risk Delta.
    So this should be used as just an example.
    The formula will still be used for Risk Ratings lower than 80 that are not shown on the chart, and will also be used for Negative Reputation Scores that are not neatly rounded to a 0.5 number.
    Also the proprietary variables are also subject to change, as we continue to fine tune the formula.
    So the chart you've posted is a good example of the type of Deltas that the formula can output.
    Because of this calculated Delta being added to the Risk Rating, the same attack coming from a known Negative Reputation Public Address will wind up with a Higher Risk Rating than the same attack coming from a Private IP Address (or even the same Public Address when not using Global Correlation).
    The sensor then has features for how it can then make use of the Risk Rating.
    And I will talk about this in the next post. I am limited by the number of characters in a single post or I would have put it into this post.

  • Global correlation events

    I have an ASA 5510 with an SSM-10 module. I have global correlation turned on and updating. When I look at the dashboard's "Global Correlation Report" I see packets that have been denied by global correlation. Can someone tell me how global correlation events are logged? I'd like to be able to see the raw data associated with the global correlation.
    Thanks.

    Hi,
    Take a look at this:
    http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_collaboration.html#wp1065809
    As can be seen, whenever "global correlation" causes any kind of action to be taken by the IPS it produces an alert unless the packet is being denied by "reputation filtering" which does not produce any kind of alert. Also, "This feature only applies to global correlation  inspection where the traffic is allowed if no specific signature is  matched".
    I am not sure of all those fields in then alert but i have seen at least some of them. If you are not seeing any alerts with those fields, then global correlation may not be seeing any instances where it has had to modify the risk ratings and take appropriate actions for it, that is, you may not be receiving any kind of such packets from malicious hosts at all in the first place.
    Also, if you have "reputation filtering" on, you might want to turn it OFF to ensure it is not causing this behavior.
    Rregards,
    Prapanch

  • Cisco IPS (global correlation) is downloading lots of updates from the iron-port website

    I have query on Global correlation.
    Following is the observed behavior
    Scenario 1:
    Global Correlation Inspection: ON (Standard)
    Reputation Filter: ON
    Result: Global correlation downloads in bytes or KBs (observed on proxy)
    Scenario 2:
    Global Correlation Inspection: OFF
    Reputation Filter: ON
    Result: Global correlation downloads 4-5 MB every 5 Minutes (observed on proxy)
    This behavior has been observed on both IPS devices one by one. What we wanted the clarity on is why is does global correlation download so much of data when it is OFF, and downloads only minimal data when ON. The equation does not seem to be right.
    Request you for your prompt response.
    Regards,
    Neal

    Both global correlation and reputation filtering retrieve updates from the SensorBase network, or IronPort. By default, they communicate with the network every five minutes. This value cannot be changed by the IPS administrator.

  • Global Correlation and Network Participation - what's the value of it ???

    Hi security gurus!
    Can someone please shed me more light on the value of Global Correlation and Network Participation available at IPS 7.x
    We've enabled it on the clients IPS appliances and now the only information I see is some cryptic reports seen at IDM gadgets.
    It says that the reputation filtering is 100% under Percentage of malicious packets indentified. So what ?
    How would I know exactly what those packets are and where did they come from?
    Other metrics are Global Correlation inspection and Traditional IPS Detection techniques are 0%
    What does it mean? Doesn't something work ? Why are they 0% ?
    How is this normally sold to the customer if there's no credible information about it?
    Eugene

    Hi,
    I think this link will help you http://docs.oracle.com/cd/B14117_01/network.101/b10776/listener.htm

  • "Global Correlation" = Critical - Cisco AIP-SSM-20

    We are getting this error on both IME and IDM. What causes this, and how does one resolve it?
    We are also not getting new events in IME - could this be related to the problem?

    correct..The sensor must operate in Inline mode so that the Global Correlation features can increase efficacy by being able to use the inline deny actions.
    http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/ime/ime_collaboration.html

  • Global Correlation Status

    Hello Everyone,
    i'm trying to enable global correlation, but, after apply the configuration, i see the status bellow:
    service global-correlation
    network-participation off
    global-correlation-inspection-influence aggressive
    test-global-correlation off
    exit
    service aaa
    exit
    service analysis-engine
    virtual-sensor vs0
    physical-interface GigabitEthernet0/1
    exit
    exit
    IPS-SITE-BACKUP#
    IPS-SITE-BACKUP#
    IPS-SITE-BACKUP#
    IPS-SITE-BACKUP# show health
    Overall Health Status                                   Green
    Health Status for Failed Applications                   Green
    Health Status for Signature Updates                     Green
    Health Status for License Key Expiration                Green
    Health Status for Running in Bypass Mode                Green
    Health Status for Interfaces Being Down                 Green
    Health Status for the Inspection Load                   Green
    Health Status for the Time Since Last Event Retrieval   Green
    Health Status for the Number of Missed Packets          Green
    Health Status for the Memory Usage                      Green
    Health Status for Global Correlation                    Not Enabled
    Health Status for Network Participation                 Green
    Why the status is "not enabled"?
    Obs: Downloads ok via proxy server.
    Thanks.
    Rafael

    Hello Rafael,
    Why the status is "not enabled
    The status is not enabled because the participation of your IPS in the global correlation is off.
    There are 3 states related to Global Correlation:
    -Full
    -Partial
    -Off
    Please change that and it should working, You need to have a DNS server set up in your IPS, if not Global Correlation will not work.
    Julio
    Rate the helpful posts

  • Global correlation update

    Hi,
    Will the IPS go offline during a global correlation update? We are running sensor version 7.1.(7)E4 and are noticing drops due to the IPS being unavailable. The timing of theses matches global correlation updates on the IPS.                      

    We are receiving the following log entry when global correlation updates.
    %ASA-3-420001: IPS card not up and fail-close mode used, dropping TCP packet from InterfaceA:x.x.x.x/xx to InterfaceB:y.y.y.y/yy

  • SSM-AIP 7.0(1) Global Correlation config nightmare!

    Thanks, Cisco, for creating a Management nightmare with your "Global Correlation" option in version 7.0...
    Lets start with the SSM-AIP-20 Management interface...
    We have an OOB Management network, with a single POI into this through a separate PIX515E appliance. Both the ASA5540 AND the SSM-AIP-20 reside on this network.
    The first issue was in Routing, since the ASA sees the Management network as "directly attached", and we ROUTE the traffic through the PIX for updates on the SSM module, we had to add translation entries in the PIX515E for the SSM module (10.x.x.x Management, 172.x.x.x translated).
    This was not a big issue, but here is where the nightmare begins...
    First a note: We have the Management network locked down TIGHT, only a couple of Network Management stations allowed into that network to access these devices.
    I enabled Global Correlation in test mode, but it was "failed" every time it tried to update.. Reading other posts, I created ACL and Static NAT in the PIX515E for these IP's:
    204.15.82.17 (IP listed in the IME Global Correlation update server)
    97.65.135.170 and .137 (from another post in these forums)
    207.15.82.17 (IP found in a trace)
    Still no updates. Looking in the PIX logs, I found "no translation" entries for the following addresses:
    198.133.219.25
    209.107.213.40
    208.90.57.73
    I put these in, and it started updating! FIXED? NOT!
    This morning, it was again failing... Looked in the PIX logs again, and found these:
    77.67.85.33
    77.67.85.9
    Entered them, and the SSM is happy again. How long? Who knows?
    So, now I have NINE holes in my "secure" network, and who knows when Cisco will change or add new IP addresses to this list.
    Cisco, if you are listening - ALL access to/from the Global correlation through a single IP? PLEASE?
    (use the one listed in the IME - 204.15.82.17, for the URL "update-manifests.ironport.com")

    A few of the addresses belong to Cisco (originally ironport.com addresses from the ironport aquisition) and are used as manifest servers to provide the sensor a list of files to download.
    The sensor then downloads those files from Akamai servers. Akamai has a large number of servers across the world. Cisco sends the update to Akamai and they replicate it across their servers. When sensors try to connect to the Akamai server it does a DNS query and by controlling the DNS response it can direct sensors to an Akamai server located nearer to the sensor. This allows for better load balancing, response times, and download speeds.
    However, Akamai has a large number of servers (in the thousands I think) world wide, and you can't predict which server your specific sensor will be directed to.
    Sensor connections to the cisco servers for the manifest (file list) is on port 443, and usually to update-manifests.ironport.com URLs.
    Sensor connections to the Akamai servers for the actual file downloads are on port 80 and usually to updates.ironport.com URLs.
    The above is all based on my limited understanding of how the updates work. I may have gotten a few details wrong, but should at least give you a general idea.
    I will be working with development to get this better documented in Release Notes and Readme with the next IPS software release.

  • ASA botnet filter vs ips global correlation

    Does the global correlation include the data from botnet filter? On Cisc's site it says this on the global correlation
    Customers deploying Cisco IPS can benefit from  Global Correlation in multiple ways. First, bad traffic from known  sources is stopped immediately. This includes zero-day attacks, for  which no traditional threat prevention currently exists, advanced  persistent threats (APTs), and botnet command and control traffic

    Hello Matt,
    Check the following info:
    Cisco ASA Botnet Traffic Filter
    This paper focuses on how Cisco Security Intelligence Operations relates to botnet threat identification, and its interaction with the Cisco ASA Botnet Traffic Filter. It is important to realize that a comprehensive security deployment should include Cisco Intrusion Prevention Systems (IPS) with its reputation based Global Correlation service and IPS signatures in conjunction with the security services provided by the ASA security appliance such as Botnet Traffic Filter.
    So I would say they both provide you security based on databases from the SIO but they will not be equal on their funcionalities, that is why Cisco recommend to use both when possible,
    Regards

  • Anyone using Global Correlation?

    Hello,
    We are the AIP-10 IPS module in our ASA firewall, I am thinking of turing the Global Correlation feature on as it has been on test for a few weeks, is anyone elase using this feature?
    Thanks

    I either get the QT movie delivered on DVD-ROM or delivered on an external FW drive already in the size and format that I want. I don't use DV output (I run the video in a window on a 2nd monitor).
    I create a separate logic song for every music cue, which I find works for me. it minimises the need to fiddle with locking objects to TC when there are tempo changes etc. in order to hear the other music that I am working on in the film to get an overall global feel etc, I bounce a work in progress from each song and place them in the right place on a dedicated track in every music cue logic song. time consuming but effective.
    for the film audio, I extract it to a track from the QT and run it in logic. can be a pain when having to change offsets but I have a technique for cutting the audio file to realign it with the film if I need to offset it.
    what I would like to see is far better implementation of movies in logic in general. I tried using the detect cuts feature for a while but found it pretty much useless for me. I am still finding that logic forgets what QT was saved with a song, so I am having to relocate it again, and it irritatingly defaults to looking in the movies folder on my system drive.. so instead of fighting it, I copy the QT to that folder when I can, ie, when it is not too big a file. in general I would like a more elastic and intuitive way to glide a movie start point as far back or forward as I would like, to easily align the start point of a music cue with bar one.
    that's all I can think of for now. any other Qs just ask.

  • IPS V7 Global Correlation

    Dear all,
    IPS Correlation update will be done through the Management interface right? So I should confirm the ability of the IPS Management IP address to be able to access internet right?
    I did so, but still not able to have global correlation update, what I am having each time I enable global correlation is a boost of traffic generated from the IPS and directed to the outside that is consuming the total internet link bandwidth.
    What could be the reason behind this boost, and how may I troubleshoot the reason why the correlation is not being updated.
    Regards,

    Hi,
    I had the exact same problem that I solved to day.
    Full connectivity but still the error:
    # sh statistics global-correlation
    Network Participation:
       Counters:
          Total Connection Attempts = 0
          Total Connection Failures = 0
          Connection Failures Since Last Success = 0
       Connection History:
    Updates:
       Status Of Last Update Attempt = Failed
       Time Since Last Successful Update = 3826 minutes
       Counters:
          Update Failures Since Last Success = 764
          Total Update Attempts = 22747
          Total Update Failures = 806
       Update Interval In Seconds = 300
       Update Server = update-manifests.ironport.com
       Update Server Address = 204.15.82.17
       Current Versions:
          config = 1236210407
          drop = 1312830724
          ip = 1312830846
          rule = 1312744926
    # sh events error error warning past 12:00
    evError: eventId=1304592381890230981 severity=error vendor=Cisco
      originator:
        hostId: xxxxxxxx
        appName: collaborationApp
        appInstanceId: 458
      time: 2011/08/11 00:38:28 2011/08/11 02:38:28 GMT+01:00
      errorMessage: name=errUnclassified A global correlation update failed: Failed download of ibrs/1.1/drop/default/1313021562 :
      URI does not contain a valid ip address
    Messages, like this one, in the category - Reputation update failure - were logged 49 times in the last 14699 seconds.
    I found a tip when searching that worked for me :
    Issue the: dns-secondary-server disable to flush DNS wait for GC to update again.
    Thanks to: http://doublef.org/archives/cisco-ips-global-correlation-update-failures 
    HTH
    Edit: I see a difference in our output, you don't have the ip address in update server field:
    Update Server Address = Unknown
    Might not bee the same problem.

  • IPS-4420 Global Correlation status critcal

    How to check in the IPS 4420 is Globel correlation license are there or not?
    In IDS 4420 IDM event montor page I am facing two below problem
    1. Event Retrieval       =========== Critical
    2. Global Correlation  =========== Critical.
    I configure IPS box got to the Internet without proxy. But I don't how to check the IPS are connected to Cisco Global Correlation server?
    Why its shwoing critcal on Event Retrieval and Global Correlation.

    Are you planning to use the Global Correlation feature?
    Here is the information on Global Correlation for your reference:
    http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_collaboration.html
    If don't want to use that feature, you can disable that in the sensor health metric section so it's not showing Critical.
    Similarly, for Even Retrieval, you can just disable that in the sensor health metric section. This is only useful if your IPS events are retrieved by an external monitoring system, eg: IME.
    http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_sensor_management.html#wp2117358
    Message was edited by: Jennifer Halim

  • How to enable a dual monitor mode

    I have a MSI FX52000 VTD-128 board which suppose to support a dual monitor mode. It has D-Sub analog, DVI and VIVO connectors.
    Would it be possible to connest primary monitor to DVI and secondary to analog output or only Video Out can be used for the secondary monitor?

    Have you installed the latest "Forceware" Drivers?...I think MSI's 52.70's are great...How you should go about setting up for two displays is to go into NVIDIA Driver Control Panel>trouble shooting>Click on the "Detect Displays" Button after you connect the other monitor ...Sean REILLY875

Maybe you are looking for

  • How to create line hart with variable number of data series

    Hello, I am student and I am completely new to Flex programming but I need to urgently create an app that should have a variable number of data series but of ame type of object. eg. Profits for X,Y and Z in in run while just corp X in the next instan

  • Song and Artist display differently in landscape mode (iPod on iPhone)

    I have a CD Compilation *50 Best Songs Ever*. When I play any song from this Compilation on my iPhone, if I turn the phone to landscape mode the Artist defaults back to the Artist on the 1st track, but if I turn the phone back to upright mode the Art

  • Photo Album app and Video viewing crashes the whole phone

    Hi. Not sure whether there is already another forum for this?  I am running android 4.3. I have found that when I go into my photo album and scroll right the way down to the bottom of the page, the pictures stop showing a thumbnail and instead all I

  • Can't transfer customized ringtones to iPhone6

    Hey guys! I took songs from my iTunes library and made them into ringtones using Garage Band.  Before, I was able to transfer the customized ringtones onto my other iPhone which was a 4S.  I now have the iPhone 6 and I can't seem to transfer my old r

  • Is it possible to NOT sync apps ?

    Hi, i have an 11inch MacBooc Air ... 11 inch implies ... small hard drive. My issue, is syncing apps starts to take a lot, and I mean a lot of space when using iTunes. I have an IPad and iPhone ... and apps or games are now taking 1gb per app. Is it