The Top N report enables you to view alerts by count, for example the 10 most frequently detected attacks, during the designated time frame. The key field, Desired Number ('N') of Attack Instances for a certain parameter type, limits the number of different attacks to view. This field is in addition to those present in the Executive Summary report. For example, if you set the desired number to 10 and select the parameter to Attack, only the ten most frequently detected attacks are listed by attack name and the number of times the attack has been detected in the specified time frame.
The Top N report provides four viewing formats rather than just the three standard formats (HTML and PDF or Save as CSV). With Top N, you can supplement your view with alert information presented in bar and pie chart formats.
Tip
This report is best used for analyzing the most common attack type, source IP, destination IP, or source/destination IP pair found in alerts during a specific time frame.
Steps:
Select Analysis → Event Reporting → Traditional Reports.
The IPS Events page is displayed.
Click the Top N Attacks link.
Fill in the fields to narrow your report. The following fields are noteworthy:
Admin Domain — Select the admin domain in which to view alerts.
Note
The admin domain selected in the left pane has no impact on the reports generated. The Admin Domain drop-down list is explicitly to filter the reports that are generated.
Sensor:
All Devices is checked by default. This displays information of all devices present at the selected admin domain. To select your preference of devices, de-select All Devices and select the devices from the list box.
Include Child Admin Domains — Displays device information for child domains.
Attack Severity — Select one or more from the Informational, Low, Medium, or High severities, which relate to attack impact.
Show only Blocked Attacks? — Select Yes to view alerts that indicate attacks blocked by the device. The default for this field is No.
Alert State — Select one of the following to narrow the alerts:
View unacknowledged alerts — All unacknowledged alerts in the system for the specified time frame. If you have acknowledged alerts during your selected time range, this option suppresses those alerts.
View all alerts — (Default) both acknowledged and unacknowledged alerts for the specified time frame.
Choose one of the following time spans:
Select Attacks for this Day — Format is yyyy/mm/dd. Default is Manager server system date.
Select Attacks Between these Dates — Format is yyyy/mm/dd hh:mm:ss. Default Begin Date is "oldest alert detected time" and default End Date is Manager server system time.
Select Attacks in the past — Selects alerts from a point in the past relative to the current time. This time in the past can be months, weeks, days (Default), or hours. Type a time (yyyy/mm/dd hh:mm:ss) when the span of reporting time ends (default is Manager server system time).
Select the Report Format.
Select the Report Content delivery method. Choices are: Chart Only, Table Only, Table and Chart, Bar chart or Pie chart
Include other Attacks — Applies only to Pie Chart format, displaying all alerts that are not included by the Desired Number. All other alerts appear as "Other" in the resulting pie chart.
Desired Number ('N') Of Attack Instances. You can specify up to 1000 (10 by default). However, only the top 20 instances will be featured in the charts. Select the Top N field of interest (Type) from one of the following:
Attack — Sort by most commonly detected attacks.
Source IP — Sort by most common attack source IP address.
Destination IP— Sort by most common attack destination IP address.
Source/Destination IP Pair — Sort by most common occurrence of a specific source-to-destination IP address attack path.
Attack Sub Category — Sort by most commonly detected attack subcategories. Examples of subcategories are port scan, protocol violation, and worm.
Protocol — Sort by most commonly attacked protocols
Service — Sort by most commonly attacked services
NSLookUp — Check the NSLookUp option to retrieve the host name corresponding to the IP address in the generated report.
Select the Sort By Attack Severity check box to include the attack severity.
Note
NSLookUp is available only for Source IP, Destination IP or both.
Select the Sort By Attack Severity check box to include the attack severity.
Click Run Report.