Skip to Main Content
SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide: Exam 500-285
book

SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide: Exam 500-285

by Todd Lammle, Alex Tatistcheff, John Gay
October 2015
Intermediate to advanced content levelIntermediate to advanced
432 pages
9h 55m
English
Sybex
Content preview from SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide: Exam 500-285

Chapter 11 Correlation Policy

THE SSFIPS EXAM TOPICS COVERED IN THIS CHAPTER INCLUDE THE FOLLOWING:

  • ✓ 11.1 Describe the components of a correlation policy
  • ✓ 11.2 Understand the process for creating a white list
  • ✓ 11.3 Describe the purpose and creation of traffic profiles
  • ✓ 11.4 Be familiar with the types of responses available when dealing with correlation policies

Correlation policy is an often overlooked but useful feature of the FireSIGHT System. The features available in this area concentrate on detection of unusual activity rather than specific intrusion or malware events. By using correlation rules, white lists, and traffic profiles, we can detect network or host behaviors that may be an indication of malicious activity. In this chapter, ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

CCIE Security v4.0 Practice Labs

CCIE Security v4.0 Practice Labs

Natalie Timms
CCNA Data Center DCICT 200-155 Official Cert Guide

CCNA Data Center DCICT 200-155 Official Cert Guide

Navaid Shamsee, David Klebanov, Hesham Fayed, Ahmed Afrose, Ozden Karakok

Publisher Resources

ISBN: 9781119155034Purchase book