40-13
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter40 Managing IPS Anomaly Detection
Configuring Anomaly Detection
Histogram Dialog Box
Use the Histogram dialog box to create or modify entries in a histogram. The histograms you create or
modify override the default histograms that anomaly detection generates. For detailed information about
how these histograms are used, see:
Understanding Anomaly Detection Thresholds and Histograms, page 40-9
Configuring Anomaly Detection Thresholds and Histograms, page 40-11
Navigation Path
Do one of the following from the Anomaly Detection policy (see Configuring Anomaly Detection,
page 40-6):
On the TCP Protocol, UDP Protocol, or Other Protocol sub tabs on the Internal Zone, Illegal Zone,
or External Zone tabs, select a row in the Threshold Histogram table and click the Edit Row button.
On the Add or Modify Dest or Protocol Map dialog boxes, click the Add Row button, or select a
row and click the Edit Row button. For information on opening the map dialog boxes, see Dest Port
or Protocol Map Dialog Box, page 40-12.
Override Scanner Settings Whether to override the scanner settings for this service or protocol.
You must select this option to enable the remaining fields on the dialog
box.
Scanner Threshold The scanner threshold for this port or protocol. The range is 5 to 1000.
The default is 200.
Threshold Histogram table The histograms for this port or protocol. If you leave the table empty,
the default histograms are used. You can have up to three rows, for low,
medium, and high numbers of destination addresses, with different
threshold levels (source addresses) for each.
To add a threshold, click the Add Row button and fill in the
Histogram Dialog Box, page 40-13. The Add button is disabled if
you already have three rows.
To edit a threshold, select it and click the Edit Row button. You
cannot change the destination bucket to one that is already defined
in the table.
To delete a threshold, select it and click the Delete Row button.
Any buckets not included in the table use the default histogram for
the bucket.
Table40-2 Destination Port or Protocol Map Dialog Box (Continued)
Element Description