Fortinet FortiDB manual General Pudr Steps, Parameterized User-Defined Rule Flow Diagram

Page 14

Chaining with Parameterized User-Defined Rules

Rule Chaining

General PUDR Steps

The general step for creating a chain that uses a PUDR are:

1In UBM, define an Object, User, or Session policy that will be your Source Rule.

2In UBM, define a PUDR that will be your Target Rule

3In the Rule Chaining module, define a chain which associates the UBM policy and the PUDR.

PUDR Process

Parameterized User-Defined Rule Flow Diagram

The PUDR process involves these steps.

1The source rule is violated and an alert is generated.

2FortiDB MA determines if there is a PUDR that is chained to the source rule.

If a rule is chained, FortiDB MA fetches the information on the chain relationship

3FortiDB MA checks to see if the source rule is to be run immediately or not.

4FortiDB MA checks to see if the chained rule is a PUDR vs. a regular policy

aIf a regular UDR, FortiDB MA runs the UDR without passing any variables.

bIf the rule is a PUDR and is set to be run immediately, FortiDB MA passes the parameters defined in the rule chain to the PUDR.

cIf the rule is a PUDR and is set to be run with the schedule settings of the source rule, FortiDB MA indicates that parameters have to be passed for the successful execution of the PUDR.

5An alert is generated for the PUDR.

 

FortiDB Version 3.2 Utilities User Guide

12

15-32000-81369-20081219

Image 14
Contents Utilities User Guide FortiDB Utilities User Guide TrademarksTable of Contents Index FortiDB MA Utilities Auto Discovery Selecting Addresses for Auto-DiscoverySelecting Non-Standard Ports for Auto-Discovery Results from Auto-DiscoveryMS-SQL Discovered Database Information Populating Connection FormMS-SQL Connection Summary Connection Summary Button Connection Summary OutputRule Chaining Setting Screen Rule ChainingRule Chaining Chaining with Parameterized User-Defined Rules Parameterized User-Defined Rule Flow Diagram General Pudr StepsDisabled Parameter Checkboxes Validating the Pudr before SavingItem Setting for Session Policy Example of Chaining to a PL/SQL-based PudrPolicy Settings for Suspicious Login Time Immediate Resulting Killed Session Table Columns That Could Appear in AlertsChained-Rule Alerts UBM Session Policy and Pudr Multiple Source-Rule-Violation Behavior DB ExampleRule Chaining Alert Report Manager Setting a Report ScheduleSetting a Timer-based Schedule Setting a Timer-Based Schedule Deleting a Previously Set Timer ScheduleSetting a Calendar-based Schedule Deleting a Timer ScheduleSetting a Calendar-Based Schedule Setting a Combined ScheduleSetting a Randomized Interval Setting a Randomized IntervalSpecifying Report Parameters Reporting by TimeEnabling Email Recipients ARM Reporting by Time ARM Reporting by Time Calendar Pop-upNew Report Setting Screen top New Reports MenuNew Report Setting Screen bottom Saved and Enabled Report Using the Select Checkbox to Affect Multiple ReportsStatus Menu Status Dialog Activating ARMRunning and Analyzing Reports View Reports Dropdown List on Current Reports ScreenChoosing Summary Report Action Current Report ConfigurationReport Summary Action Summary-Action Output TypesReport Size Archiving Reports Report Detailed ActionLimitation Scheduling Using This FeatureCustom Reports Custom ReportsTime-only Schedule Settings Daily Schedule Settings Customer and Company Information Weekly Schedule SettingsMonthly Schedule Settings Custom Reports Main Report and Template Generation and ManagementCompany Information Dialog Adding a Report Adding ReportsModifying Reports Deleting a Report Deleting ReportsModifying a Report Modifying Report Templates Templates Manager Modifying a Template Generating ReportsReport Result Generated Html Report Example Report History Report HistoryReports radio button on the User Administration screen Licensing and AdministrationUser Administration for Custom Reports and SOX Reports Property Purpose Possible Values DefaultProperty Purpose Possible Values Default1 LimitationsSOX Compliance Reports SOX Reports within Custom Reports ManagerCommon Report Header Fields General Setup InstructionsReports and Acronyms Report Name AcronymReport Body Columns Cobit Objectives and Setup RequirementsHistory of Privilege Changes Report HPC HPC Report SampleAbnormal or Unauthorized Changes to Data Report AUC AUC Report SampleAbnormal Use of Service Accounts Report AUS AUS Report SampleAbnormal Termination of Database Activity Report ATD ATD Report SampleEPA Report Sample End of Period Adjustments Report EPASettings Dialog for the EPA Report Case AssumptionsVerification of Audit Settings Report VAS VAS Report SampleReport Size Licensing and AdministrationArchiving Reports Verification of Audit Settings Report VAS Index