Explains how alerts notify users about significant activity or irregularities in an industrial network, categorize data, and provide warnings to aid security monitoring.
Alerts are system-generated notifications that
-
indicate significant activity or irregularities detected within an industrial network,
-
categorize information based on type, associated data, and network components, and
-
provide warnings to help with security monitoring and response.
An alert is a notification that triggers when a user-defined rule’s condition is met. Cyber Vision sends alerts through Syslog when they are raised, cleared, or their status changes. For details about this configuration, see Enable or disable syslog notifications for an alert type.
|
Feature |
Release Information |
Feature Description |
|---|---|---|
|
Pause and resume individual alert rules |
Release 5.6.x |
You can pause or resume individual alert rules. Pausing a rule does not affect other rules associated with the same alert type. Alert type-level pause and resume are no longer available. |
|
MITRE ATT and CK information for Intrusion Detection alerts |
Release 5.6.x |
Intrusion Detection alerts display the MITRE ATT and CK tactics and techniques associated with the Snort rule that generated the alert. |
|
Assets with unexpected behaviors alert type |
Release 5.6.x |
Cisco Cyber Vision monitors the assets that are part of the alert rules, and raises an alert when any of those assets are involved in selected behaviors within the configured time window. |
|
Alert rule configuration changes |
Release 5.6.x |
You can no longer configure alert rules for functional groups. When you upgrade to Release 5.6.x, Cyber Vision automatically deletes existing alert rules configured for functional groups. |
|
Network Scanner alert type |
Release 5.6.x |
The Network Scanner alert type identifies network reconnaissance and scanning attempts. IP addresses specified in the Allowed Scanner list are excluded and do not generate alerts. |
|
Inactive assets alert type |
Release 5.5.x |
Inactive assets alert type detects assets that stop communicating due to failure or misconfiguration. Define custom rules for the inactivity period to reduce manual monitoring. |
|
Intrusion detection alert type |
Release 5.5.x |
Intrusion detection alert type monitors network traffic using the Snort intrusion detection system. It raises an alert when suspicious or malicious network activity is detected on monitored assets, based on Snort rules. |
|
Assets with unexpected external communications alert type |
Release 5.5.x |
Assets with unexpected external communications alert type monitors asset communications. It raises an alert if an asset communicates to external IP addresses or domains. |
|
Network-based organization hierarchy alert configuration |
Release 5.4.x |
You can configure alerts at the organization hierarchy level with one additional entity type: Organization Hierarchy (Networks). The system changes all existing alert rules with the entity type Organization Hierarchy to Organization Hierarchy (Sensors) automatically. |
|
Mute or unmute alert instances for prohibited vendor alert type |
Release 5.4.x |
You can use the mute and unmute feature to control prohibited vendor alerts. Mark alert instances as reviewed and not urgent so they remain in the system but are not active. Select the duration to mute an alert instance; after that period, the alert becomes active again. |
|
Active and cleared alerts |
Release 5.3.x |
The Alerts page displays two types of alerts:
|
|
Pause alert creations |
Release 5.3.x |
You can pause an alert type in the Configure > Alerts |
|
Change vulnerability scoring system for alerts |
Release 5.3.x |
The Cisco Security Risk Score is the default scoring system applied to alert configurations. However, you can choose to update an alert configuration to apply the CVSS scoring system instead. |
|
Alert for severe vulnerabilities in monitored entities |
Release 5.3.x |
Create and edit rules for the Severe vulnerabilities in monitored entities alert based on the Cisco Security Risk Score or the CVSS score. |
|
Alert for prohibited vendors |
Release 5.3.x |
The Configure > Alerts page contains a default alert for prohibited vendors. The alert rule is based on an editable list of prohibited vendors. |