以下類型的網路行為會升高 Stealthwatch C&C 數值,每一種行為的積分如附表。
|
Name of security event
| Number of points assigned by default
|
Beaconing Host
| 10
|
Bot Infected Host - Attempted C&C Activity
| 50000
|
Bot Infected Host - Successful C&C Activity
| 10000
|
Command And Control Host
| 50000
|
Fake Application Detected
| 1000
|
Long Ping
| 1
|
SSH Reverse Shell
| 1000
|
Suspect Long Flow
| 1000
|
Suspect Quiet Long Flow
| 1500
|