2.10. Threat prevention

Threat prevention.

2.10.1. IPS

Intrusion prevention system.

2.10.1.1. Double encoding of URL

Description

Total number of times HTTP Normalization has found an URL with double encoding.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/url_double_encoding

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1060[.0]   (STREAM-MIB)

MIB Name

ssmIPSDoubleEncodingURL

MIB Type

Counter64

2.10.1.2. Flows scanned

Description

Total number of flows scanned by the IPS engine.

Type

Unsigned 64-bit integer

Unit

Flows

Category

Counter

Stat Path

/threat_prevention/ips/flows_scanned

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1075[.0]   (STREAM-MIB)

MIB Name

ssmIPSFlowsScanned

MIB Type

Counter64

2.10.1.3. Inspection errors

Description

Total number of inspection errors seen in the inspection engine.

Type

Unsigned 64-bit integer

Unit

Errors

Category

Counter

Stat Path

/threat_prevention/ips/inspection_errors

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1070[.0]   (STREAM-MIB)

MIB Name

ssmIPSInspectionErrors

MIB Type

Counter64

2.10.1.4. Invalid HEX encoding of URL

Description

Total number of times HTTP Normalization has found an URL with invalid HEX encoding.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/url_invalid_hex

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1055[.0]   (STREAM-MIB)

MIB Name

ssmIPSInvalidHEXURL

MIB Type

Counter64

2.10.1.5. Invalid UTF8 URL

Description

Total number of times HTTP Normalization has found an URL with invalid UTF8 format.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/url_invalid_utf8

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1050[.0]   (STREAM-MIB)

MIB Name

ssmIPSInvalidUTF8URL

MIB Type

Counter64

2.10.1.6. Custom signatures

Description

Total number of custom signatures available to the system.

Type

Unsigned 32-bit integer

Unit

Signatures

Category

Momentaneous

Stat Path

/threat_prevention/ips/signatures_custom

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1015[.0]   (STREAM-MIB)

MIB Name

ssmIPSCustomSignatures

MIB Type

Unsigned32

2.10.1.7. Rejected signatures

Description

Total number of signatures rejected by the system due to bad formatting.

Type

Unsigned 32-bit integer

Unit

Signatures

Category

Momentaneous

Stat Path

/threat_prevention/ips/signatures_rejected

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1020[.0]   (STREAM-MIB)

MIB Name

ssmIPSRejectedSignatures

MIB Type

Unsigned32

2.10.1.8. Vendor signatures

Description

Total number of vendor signatures available to the system.

Type

Unsigned 32-bit integer

Unit

Signatures

Category

Momentaneous

Stat Path

/threat_prevention/ips/signatures_vendor

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1010[.0]   (STREAM-MIB)

MIB Name

ssmIPSVendorSignatures

MIB Type

Unsigned32

2.10.1.9. Scan limit exceeded

Description

Total number of times the scan limit has been exceeded, resulting in terminated IPS scanning for a flow.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/scanlimit_exceeded

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1080[.0]   (STREAM-MIB)

MIB Name

ssmIPSScanLimitExceeded

MIB Type

Counter64

2.10.1.10. Modified date

Description

Modified date of vendor signature database.

Type

String

Stat Path

/threat_prevention/ips/signaturedb_date

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1030[.0]   (STREAM-MIB)

MIB Name

ssmIPSSignatureDBDate

MIB Type

DisplayString

2.10.1.11. Version

Description

Version number of vendor signature database.

Type

String

Stat Path

/threat_prevention/ips/signaturedb_ver

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1025[.0]   (STREAM-MIB)

MIB Name

ssmIPSSignatureDBVersion

MIB Type

DisplayString

2.10.1.12. Threats detected

Description

Total number of times the system has detected a potential threat.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/threats_detected

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1040[.0]   (STREAM-MIB)

MIB Name

ssmIPSThreatsDetected

MIB Type

Counter64

2.10.1.13. Threats protected

Description

Total number of times the system has protected against a potential threat.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/threats_protected

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.1045[.0]   (STREAM-MIB)

MIB Name

ssmIPSThreatsProtected

MIB Type

Counter64

2.10.1.14. Rules[..]

The row in a table of IPS rule statistics.

Rule row index

Description

IPS Rule row index.

Type

32-bit integer

Category

Momentaneous

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.3010.1.1[.n]   (STREAM-MIB)

MIB Name

ssmIPSRuleIndex

MIB Type

Integer32

Rule name

Description

IPS rule name.

Type

String

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.3010.1.2[.n]   (STREAM-MIB)

MIB Name

ssmIPSRuleName

MIB Type

DisplayString

Signatures actually used by the rule

Description

Number of signatures actually used by the rule, not counting signatures rejected due to port, service etc.

Type

Unsigned 32-bit integer

Unit

Signatures

Category

Momentaneous

Stat Path

/threat_prevention/ips/rules/[..n]/signatures_used

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.3010.1.1010[.n]   (STREAM-MIB)

MIB Name

ssmIPSRuleSignaturesUsed

MIB Type

Unsigned32

Signatures selected by the rule

Description

Number of signatures selected by the rule.

Type

Unsigned 32-bit integer

Unit

Signatures

Category

Momentaneous

Stat Path

/threat_prevention/ips/rules/[..n]/signatures_selected

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.3010.1.1005[.n]   (STREAM-MIB)

MIB Name

ssmIPSRuleSignaturesSelected

MIB Type

Unsigned32

Double encoding of URL

Description

Number of times HTTP Normalization has found an URL with double encoding using this rule.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/rules/[..n]/url_double_encoding

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.3010.1.1060[.n]   (STREAM-MIB)

MIB Name

ssmIPSRuleDoubleEncodingURL

MIB Type

Counter64

Inspection errors

Description

Number of inspection errors seen in the inspection engine using this rule.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/rules/[..n]/inspection_errors

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.3010.1.1070[.n]   (STREAM-MIB)

MIB Name

ssmIPSRuleInspectionErrors

MIB Type

Counter64

Invalid HEX encoding of URL

Description

Number of times HTTP Normalization has found an URL with invalid HEX encoding using this rule.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/rules/[..n]/url_invalid_hex

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.3010.1.1055[.n]   (STREAM-MIB)

MIB Name

ssmIPSRuleInvalidHEXURL

MIB Type

Counter64

Invalid UTF8 URL

Description

Number of times HTTP Normalization has found an URL with invalid UTF8 format using this rule.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/rules/[..n]/url_invalid_utf8

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.3010.1.1050[.n]   (STREAM-MIB)

MIB Name

ssmIPSRuleInvalidUTF8URL

MIB Type

Counter64

Scan limit exceeded

Description

Number of times the scan limit has been exceeded, resulting in terminated IPS scanning for a flow using this rule.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/rules/[..n]/scanlimit_exceeded

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.3010.1.1080[.n]   (STREAM-MIB)

MIB Name

ssmIPSRuleScanLimitExceeded

MIB Type

Counter64

Threats detected

Description

Number of times the system has detected a potential threat using this rule.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/rules/[..n]/threats_detected

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.3010.1.1040[.n]   (STREAM-MIB)

MIB Name

ssmIPSRuleThreatsDetected

MIB Type

Counter64

Threats protected

Description

Number of times the system has protected against a potential threat using this rule.

Type

Unsigned 64-bit integer

Unit

Hits

Category

Counter

Stat Path

/threat_prevention/ips/rules/[..n]/threats_protected

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2010.3010.1.1045[.n]   (STREAM-MIB)

MIB Name

ssmIPSRuleThreatsProtected

MIB Type

Counter64

2.10.2. SSL inspection

SSL Inspection.

2.10.2.1. Failed interceptions

Description

Total number of failed interceptions.

Type

Unsigned 32-bit integer

Unit

Attempts

Category

Counter

Stat Path

/threat_prevention/sslinspection/failed_interceptions

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2020.1005[.0]   (STREAM-MIB)

MIB Name

ssmSSLInspFailedIntercepts

MIB Type

Counter32

2.10.2.2. Successful interceptions

Description

Total number of successful interceptions.

Type

Unsigned 32-bit integer

Unit

Connections

Category

Counter

Stat Path

/threat_prevention/sslinspection/successful_interceptions

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2020.1010[.0]   (STREAM-MIB)

MIB Name

ssmSSLInspSuccessfulIntercepts

MIB Type

Counter32

2.10.2.3. Profiles[..]

The row in a table of SSL Inspection profile statistics.

Profile name

Description

SSL Inspection profile name.

Type

String

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2020.3010.1.2[.n]   (STREAM-MIB)

MIB Name

ssmSSLInspectionProfileName

MIB Type

DisplayString

Profile row index

Description

SSL Inspection profile row index.

Type

32-bit integer

Category

Momentaneous

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2020.3010.1.1[.n]   (STREAM-MIB)

MIB Name

ssmSSLInspectionProfileIndex

MIB Type

Integer32

Failed client TLS connections

Description

Number of failed client TLS connections for this profile.

Type

Unsigned 32-bit integer

Unit

Attempts

Category

Counter

Stat Path

/threat_prevention/sslinspection/profiles/[..n]/client_failed_tls

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2020.3010.1.1005[.n]   (STREAM-MIB)

MIB Name

ssmClientFailedTLS

MIB Type

Counter32

Failed server TLS connections

Description

Number of failed server TLS connections for this profile.

Type

Unsigned 32-bit integer

Unit

Attempts

Category

Counter

Stat Path

/threat_prevention/sslinspection/profiles/[..n]/server_failed_tls

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2020.3010.1.1010[.n]   (STREAM-MIB)

MIB Name

ssmServerFailedTLS

MIB Type

Counter32

Successful client TLS connections

Description

Number of successful client TLS connections for this profile.

Type

Unsigned 32-bit integer

Unit

Connections

Category

Counter

Stat Path

/threat_prevention/sslinspection/profiles/[..n]/client_successful_tls

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2020.3010.1.1015[.n]   (STREAM-MIB)

MIB Name

ssmClientSuccessfulTLS

MIB Type

Counter32

Successful server TLS connections

Description

Number of successful server TLS connections for this profile.

Type

Unsigned 32-bit integer

Unit

Connections

Category

Counter

Stat Path

/threat_prevention/sslinspection/profiles/[..n]/server_successful_tls

MIB OID

1.3.6.1.4.1.5089.3.2.2085.2020.3010.1.1020[.n]   (STREAM-MIB)

MIB Name

ssmServerSuccessfulTLS

MIB Type

Counter32