10-4
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter10 Co nfiguring Global Correlation
Understanding Network Participation
Figure 10-1 shows the role of the sensor and the global correlation servers.
Figure 10-1 IPS Management and Global Correlation Server Interaction
The global correlation servers provide information to the sensor about certain IP addresses that may
identify malicious or infected hosts. The sensor uses this information to determine which actions, if any,
to perform when potentially harmful traffic is received from a host with known reputation. Because the
global correlation database changes rapidly, the sensor must periodically download global correl ation
updates from the global correlation servers.
Caution
As with signature updates, when the sensor applies a global correlation update, it may trigger bypass.
Whether or not bypass is triggered depends on the traffic load of the sensor and the size of the
signature/global correlation update. If bypass mode is turned off, an inline sensor stops passing traffic
while the update is being applied.
For More Information
For more information about viewing global correlation statistics, see Displaying Statistics, page 17-28.
Understanding Network Participation
Network participation lets us collect nearly real-time data from sensors around the world. Sensors
installed at customer sites can send data to the SensorBase Network. These data feed in to the global
correlation database to increase reputation fidelity. Communication between sensors and the SensorBase
Network involves an HTTPS request and response over TCP/IP. Network participation gathers the
following data:
Signature ID
Attacker IP address
Attacker port
Maximum segment size
Victim IP address
Victim port
Signature version
TCP options string
Reputation score
Risk rating
Events
Config
Reputation
Telemetry
Database
Query
251234
Cisco IPS
Cisco Data Clients
(CA-Sig, Sec-Analysis) Reputation
Server(s)
Management Tools
(CLI/IDM/IME/
CSM/MARS)
Reputation
Database
Reputation
Client
Sensor
Application Event
Manager
UI
Support