Presentation is loading. Please wait.

Presentation is loading. Please wait.

Priority between clause rules. Wiki Cisco Usr Sales Usr Sales Usr HTTP Hi-Scan (HTTP| FTP) -> Low-Scan.

Similar presentations


Presentation on theme: "Priority between clause rules. Wiki Cisco Usr Sales Usr Sales Usr HTTP Hi-Scan (HTTP| FTP) -> Low-Scan."— Presentation transcript:

1 Priority between clause rules

2 Wiki Cisco Usr Sales Usr Sales Usr HTTP Hi-Scan (HTTP| FTP) -> Low-Scan

3 Wiki Cisco Usr Sales Usr Sales Usr Subject: HI_Sec_HTTP Clause: R1: Sales->Wiki: Subject: Hi_sec_HTTP R2: Cisco ->Wiki: Subject: Low_sec_HTTP Subject: Low_sec_FTP Clause: R1: Sales->Wiki: Subject: Hi_sec_HTTP R2: Cisco ->Wiki: Subject: Low_sec_HTTP Subject: Low_sec_FTP Filter: HTTP Action: Hi-Scan Filter: HTTP Action: Hi-Scan Subject: Low_Sec_HTTP Filter: HTTP Action: Low-Scan Filter: HTTP Action: Low-Scan Subject: Low_Sec_FTP Filter: FTP Action: Low-Scan Filter: FTP Action: Low-Scan Problem: If Sales guy is accessing FTP he would match R1 that will deny him access. He should match R2.

4 Wiki Cisco Usr Sales Usr Sales Usr Clauses: R1: Sales, -> Wiki, (HTTP | FTP) Subject: Hi_scan R2: Cisco ->Wiki, (HTTP | FTP|SSH): Subject: Low-scan Clauses: R1: Sales, -> Wiki, (HTTP | FTP) Subject: Hi_scan R2: Cisco ->Wiki, (HTTP | FTP|SSH): Subject: Low-scan Subject: Low Scan Action: Low-Scan Contract wide Subject: HI_Scan Action: Hi-Scan Possible solution

5 Wiki Cisco Usr Sales Usr Sales Usr Clauses: (First-match) R2: Cisco ->Wiki: Subject: Low_sec_HTTP Subject: Low_sec_FTP Clauses: (First-match) R2: Cisco ->Wiki: Subject: Low_sec_HTTP Subject: Low_sec_FTP Subject: Low_Sec_HTTP Filter: HTTP Action: Low-Scan Filter: HTTP Action: Low-Scan Subject: Low_Sec_FTP Filter: FTP Action: Low-Scan Filter: FTP Action: Low-Scan Subject: HI_Sec_HTTP Clauses: (First-match) R1: Sales->Wiki: Subject: Hi_Sec_HTTP Clauses: (First-match) R1: Sales->Wiki: Subject: Hi_Sec_HTTP Filter: HTTP Action: Hi-Scan Filter: HTTP Action: Hi-Scan Contract wide Contract Restricted Solves it.

6 Wiki Cisco Usr Sales Usr Sales Usr Clauses: (First-match) R2: Cisco ->Wiki: Subject: Low_sec_HTTP Subject: Low_sec_FTP Subject: Low_sec_SSH Clauses: (First-match) R2: Cisco ->Wiki: Subject: Low_sec_HTTP Subject: Low_sec_FTP Subject: Low_sec_SSH Subject: Lo_Sec_HTTP Filter: HTTP Action: Lo-Scan Filter: HTTP Action: Lo-Scan Subject: Lo_Sec_FTP Filter: FTP Action: Lo-Scan Filter: FTP Action: Lo-Scan Subject: HI_Sec_HTTP Clauses: (First-match) R1: Sales->Wiki: Subject: Hi_sec_HTTP Subject: Hi_sec_FTP Clauses: (First-match) R1: Sales->Wiki: Subject: Hi_sec_HTTP Subject: Hi_sec_FTP Filter: HTTP Action: Hi-Scan Filter: HTTP Action: Hi-Scan Contract wide Contract Restricted Sales Usr Enemy Nation Sales Usr Enemy Nation Contract Further Restricted Subject: HI_Hi_Sec_HTTP Clauses: R1: Sales & Outside ->Wiki: Subject: Hi-Hi-scan_HTTP Clauses: R1: Sales & Outside ->Wiki: Subject: Hi-Hi-scan_HTTP Filter: HTTP Action: Hi-Hi-Scan Filter: HTTP Action: Hi-Hi-Scan Subject: HI_Sec_FTP Filter: HTTP Action: Hi-Scan Filter: HTTP Action: Hi-Scan Subject: Lo_Sec_SSH Filter: SSH Action: Lo-Scan Filter: SSH Action: Lo-Scan Problem: For each such conflict I am forced to create hierarchy. It is getting complex

7 Wiki Cisco Usr Sales Usr Sales Usr Clauses: R0: Sales, Enemy Nation -> Wiki, HTTP Subject: Hi_Hi_scan R1: Sales, -> Wiki, (HTTP | FTP) Subject: Hi_scan R2: Cisco ->Wiki, (HTTP | FTP|SSH): Subject: Low-scan Clauses: R0: Sales, Enemy Nation -> Wiki, HTTP Subject: Hi_Hi_scan R1: Sales, -> Wiki, (HTTP | FTP) Subject: Hi_scan R2: Cisco ->Wiki, (HTTP | FTP|SSH): Subject: Low-scan Subject: Low Scan Action: Low-Scan Contract wide Sales Usr at Enemy Nation Sales Usr at Enemy Nation Subject: Hi_Hi_scan Action: Hi-Hi-Scan Subject: HI_Scan Action: Hi-Scan Possible solution


Download ppt "Priority between clause rules. Wiki Cisco Usr Sales Usr Sales Usr HTTP Hi-Scan (HTTP| FTP) -> Low-Scan."

Similar presentations


Ads by Google