<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with Risk Rating calculation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-with-risk-rating-calculation/m-p/1560174#M66395</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's the config guide on how risk rating is calculated:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_event_action_rules.html#wp1067121"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_event_action_rules.html#wp1067121&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Sep 2010 01:12:09 GMT</pubDate>
    <dc:creator>Jia Liu</dc:creator>
    <dc:date>2010-09-30T01:12:09Z</dc:date>
    <item>
      <title>Help with Risk Rating calculation</title>
      <link>https://community.cisco.com/t5/network-security/help-with-risk-rating-calculation/m-p/1560173#M66394</link>
      <description>&lt;P&gt;I'm trying to understand the risk rating calculation on an IPS4240 sensor.&amp;nbsp; From what I can tell, it looks like there are some additional parameters added to the equation that are not easy to determine.&amp;nbsp; It looks like the ARR (Attack Relevancy Rating) and/or WLR (Watch List Rating) are making changes (i.e. being added to the RR), but I cannot find any values for these.&amp;nbsp; Are there default values for ARR that the system uses?&amp;nbsp; What about the WLR, can that be viewed anywhere?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Pat&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:08:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-risk-rating-calculation/m-p/1560173#M66394</guid>
      <dc:creator>pcoughlin01</dc:creator>
      <dc:date>2019-03-10T12:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Risk Rating calculation</title>
      <link>https://community.cisco.com/t5/network-security/help-with-risk-rating-calculation/m-p/1560174#M66395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's the config guide on how risk rating is calculated:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_event_action_rules.html#wp1067121"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_event_action_rules.html#wp1067121&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 01:12:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-risk-rating-calculation/m-p/1560174#M66395</guid>
      <dc:creator>Jia Liu</dc:creator>
      <dc:date>2010-09-30T01:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Risk Rating calculation</title>
      <link>https://community.cisco.com/t5/network-security/help-with-risk-rating-calculation/m-p/1560175#M66396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I've seen that too, but it doesn't tell you the values that actually get added.&amp;nbsp; It says that the ARR is a derived value (relevant, unknown, or not relevant), which is determined at alert time, however it doesn't tell you what the numeric value actually is.&amp;nbsp; From events that I'm seeing, I can determine most of the other values, but I still can't come up with the same RR that the sensor does, so I'm guessing that there's some ARR value that's added.&amp;nbsp; In other words, does a "relevant" o/s get 50 points, while an unknown only gets 20?&amp;nbsp; It's those values that I'm looking for.&amp;nbsp;&amp;nbsp; Also, on the event in question, the signature lists the os type as "general" (I think), which also looks to have some internal ARR value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help with those ARR values is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Pat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 15:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-risk-rating-calculation/m-p/1560175#M66396</guid>
      <dc:creator>pcoughlin01</dc:creator>
      <dc:date>2010-09-30T15:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Risk Rating calculation</title>
      <link>https://community.cisco.com/t5/network-security/help-with-risk-rating-calculation/m-p/1560176#M66399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess below is what you are looking for:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/web/about/security/intelligence/ipsmit.html"&gt;http://www.cisco.com/web/about/security/intelligence/ipsmit.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It says the below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;Attack Relevancy Rating: &lt;/STRONG&gt;The Attack Relevancy Rating&amp;nbsp; (ARR) is an IPS-generated value that&amp;nbsp; indicates if the attack target may&amp;nbsp; be vulnerable to an event-specific attack.&amp;nbsp; This information is&amp;nbsp; normally gathered through passive operating system identification but&amp;nbsp; can also be defined by a&amp;nbsp; user or gathered through integration with the&amp;nbsp; Cisco Security Agent Management&amp;nbsp; Console. If the operating system of the&amp;nbsp; targeted device is&amp;nbsp; unknown, there is no change to the&amp;nbsp; risk rating.&amp;nbsp; However, if the&amp;nbsp; targeted device operating system is discovered to be&amp;nbsp; relevant, the risk rating&amp;nbsp; increases by 10 in both Inline and&amp;nbsp; Promiscuous modes. If the targeted device operating system is found&amp;nbsp; to&amp;nbsp; be irrelevant, the risk rating in Promiscuous mode is reduced by&amp;nbsp; 10,&amp;nbsp; and no change occurs in Inline mode."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this clears things up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 15:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-risk-rating-calculation/m-p/1560176#M66399</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-09-30T15:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Risk Rating calculation</title>
      <link>https://community.cisco.com/t5/network-security/help-with-risk-rating-calculation/m-p/1560177#M66405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Excellent, thanks.&amp;nbsp; That's what I was looking for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 17:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-risk-rating-calculation/m-p/1560177#M66405</guid>
      <dc:creator>pcoughlin01</dc:creator>
      <dc:date>2010-09-30T17:19:52Z</dc:date>
    </item>
  </channel>
</rss>

