How to create a CS-MARS Inspection Rule

Within CS-MARS there are 2 types of rules. Inspection Rules and Drop Rules. Inspection Rules allow you to trigger events based on certain triggers such as keywords, source, destination etc. Drop rule is an exception rule which MARS uses to ignore a behaviour that would otherwise trigger an event.

In this example we will configure a Inspection rule. First of all we need to define when this rule will trigger an event. For this example we will create an event every time someone saves an configuration change upon your Netscreen device. The syslog message for this is :

Jul  6 14:17:42 x.x.x.x ns200: NetScreen device_id=006403324004624  [Root]system-information-00
767: System configuration saved by [user] via web from host x.x.x.x to x.x.x.x:443 by [user]. 
(2010-07-06 19:17:41)

Steps

1. Click Rules | Inspection Rules | Add

 

2. This will take you through a wizard. For each stage select Any. Until you get to the Keyword section.
3. Enter the text you want CS-MARS to trigger on.

CS-MARS Inspection Rule - Trigger on

4. Carry on through the wizard. At the end Apply the changes.

CS-MARS Inspection Rule - Apply

5. Now when you go into the Incident Rule section again you will see your new rule. By default your new rule will be activated.

Additional Notes 

Within the previous syslog message you will notice that the message ID is 00767. CS-MARS has a list of all the device message types/IDs which is calls event types. This is useful as this allows you to build rules based on event types rather then just using keyword strings.

Rick Donato

Want to become an IT Security expert?

Here is our hand-picked selection of the best courses you can find online:
Internet Security Deep Dive course
Complete Cyber Security Course – Hackers Exposed
CompTIA Security+ (SY0-601) Certification Complete course
and our recommended certification practice exams:
AlphaPrep Practice Tests - Free Trial