CISCO-SERVICE-CONTROL-ATTACK-MIB

This MIB provides data related to different types of attacks detected by a service control entity. A service control entity is a network device which monitors and controls traffic. The service control entity is used as a platform for different service control applications which may perform monitoring operations beyond packet counting and delve deeper into the contents of network traffic. It provides programmable stateful inspection of bidirectional traffic flows and maps these flows with user/subscriber ownership. An attack is a malicious network activity with certain traffic characteristics and which is targeted on a certain network entity. An attack can be identified by its type, direction, source address, destination address and ports. Once an attack is detected, an attack filter is activated based on the type of the attack and corresponding actions are taken in the monitored network - this is referred to as attack start. For example the attack filter can drop the attacking traffic. When the attack detector identifies that the attack characteristics are no longer exist, it ends the mitigation action - what is referred to as attack end. The attack mitigation action is also referred to as attack filtering in this MIB. The time duration of attack filtering between attack start to attack end along with the direction (upstream, downstream) is also maintained by the service control entity. Attack filtering can be applied from the subscriber side to the network side, in the upstream direction. The downstream attack filtering is done from the network side to the subscriber side. This MIB also defines notifications generated by the service control entity when an attack is detected on a monitored network.

MIB content (35 objects)

Informations

Organization
Cisco Systems, Inc.
Contact info
Cisco Systems Customer Service Postal: 170 W Tasman Drive San Jose, CA 95134 USA Tel: +1 800 553-NETS E-mail: cs-excelsior-dev@cisco.com

Revisions

2013-08-16 00:00
Updates to support traps for global attacks. For this 1. A new trap is introduced: cscaGlobalAttackFilterChange. 2. A new object is introduced: cscaGlobalAtackType to describe the type of global attack. 3. A 3 groups are introduced: a. cscaMIBNotificationGroupRev1, deprecating cscaMIBNotificationGroup. b. cscaFilterObjectGroupRev1, deprecating cscaFilterObjectGroup. c. cscaMIBNotifControlGroupRev1, deprecating cscaMIBNotifControlGroup 4. A new compliance is introduced: cscaMIBComplianceRev1, deprecating cscaMIBCompliance.
2009-05-05 00:00
Initial version of this MIB module.