10-5
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter1 0 Configuring Global Correlation
Understanding Efficacy
Data gathered from the sensor health metrics
The statistics for network participation show the hits and misses for alerts, the reputation actions, and
the counters of packets that have been denied.
Note
Network participation requires a network connection to the Internet.
There are three modes for network participation:
Off—The network participation server does not collect data, track statistics, or try to contact the
Cisco SensorBase Network.
Partial Participation—The network participation server collects data, tracks statistics, and
communicates with the SensorBase Network. Data considered to be potentially sensitive is filtered
out and never sent.
Full Participation—The network participation server collects data, tracks statistics, and
communicates with the SensorBase Network. All data collected is sent except the IP addresses that
you exclude from the network participation data.
Caution
As with signature updates, when the sensor applies a global correlation update, it may trigger bypass.
Whether or not bypass is triggered depends on the traffic load of the sensor and the size of the
signature/global correlation update. If bypass mode is turned off, an inline sensor stops passing traffic
while the update is being applied.
For More Information
For more information on network participation, see Configuring Network Participation, page 10-11 .
For more information on bypass mode, see Configuring Inline Bypass Mode, page4-33.
Understanding Efficacy
Obtaining data from participating IPS clients and using that in conjunction with the existing corpus of
threat knowledge improves the efficacy of the IPS. We measure efficacy based on the following:
False positives as a percentage of actionable events
False negatives as a percentage of threats that do not result in actionable events
Actionable events as a percentage of all events
The IPS signature team uses the data to improve signature fidelity and the IPS engineering team uses the
data to better understand the various types of sensor deployment.
For More Information
For more information about reputation and risk rating, see Understanding Reputation and Risk Rating,
page 10-6.