ProCurve 6200yl User's Guide Page 64

  • Download
  • Add to my manuals
  • Print
  • Page
    / 596
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 63
3-4
Virus Throttling
Overview of Connection-Rate Filtering
Features and Benefits
Connection-rate filtering is a countermeasure tool you can use in your inci-
dent-management program to help detect an manage worm-type IT security
threats received in inbound IP traffic. Major benefits of this tool include:
Behavior-based operation that does not require identifying details
unique to the code exhibiting the worm-like operation.
Handles unknown worms.
Needs no signature updates.
Protects network infrastructure by slowing or stopping IP traffic from
hosts exhibiting high connection-rate behavior.
Allows network and individual switches to continue to operate, even
when under attack.
Provides Event Log and SNMP trap warnings when worm-like
behavior is detected
Gives IT staff more time to react before the threat escalates to a crisis.
Note When configured on a port, connection-rate filtering is triggered by IPv4
traffic received inbound with a relatively high rate of IP connection attempts.
Figure 3-1. Example of Protecting a Network from Agents Using a High IP Connection Rate To Propagate
5400zl switch with
connection-rate filtering
configured, and block
spreading option enabled.
Configuring connection-rate
filtering on the switch protects the
other devices on the network from
the high connection-rate traffic
(characteristic of worm attacks)
that is detected on the edge port
connected to device D.
Device infected with
worm-like malicious code
A
B
C
D
Port is blocked
SNMP Trap and/or
Event Log message
Management
Station
Page view 63
1 2 ... 59 60 61 62 63 64 65 66 67 68 69 ... 595 596

Comments to this Manuals

No comments