Symantec Critical System Protection Configuration Monitoring Edition Release Notes



Similar documents
Symantec Critical System Protection Agent Event Viewer Guide

Symantec Enterprise Security Manager Modules for Sybase Adaptive Server Enterprise Release Notes 3.1.0

Symantec Critical System Protection Agent Event Viewer Guide

Symantec Enterprise Security Manager Patch Policy Release Notes

Symantec Event Collector for Kiwi Syslog Daemon version 3.7 Quick Reference

Symantec Event Collector 4.3 for Microsoft Windows Quick Reference

Symantec Enterprise Security Manager Oracle Database Modules Release Notes. Version: 5.4

Veritas Cluster Server Getting Started Guide

Symantec Event Collector for Cisco NetFlow version 3.7 Quick Reference

Symantec Backup Exec System Recovery Granular Restore Option User's Guide

Symantec LiveUpdate Administrator. Getting Started Guide

Symantec Backup Exec System Recovery Exchange Retrieve Option User's Guide

Veritas Operations Manager Package Anomaly Add-on User's Guide 4.1

Symantec Integrated Enforcer for Microsoft DHCP Servers Getting Started Guide

Symantec NetBackup Desktop and Laptop Option README. Release 6.1 MP7

Symantec Security Information Manager - Best Practices for Selective Backup and Restore

Symantec Mobile Management for Configuration Manager

Veritas Operations Manager LDom Capacity Management Add-on User's Guide 4.1

Symantec Mail Security for Microsoft Exchange Management Pack Integration Guide

Symantec Client Firewall Policy Migration Guide

Symantec System Recovery 2013 Management Solution Administrator's Guide

Symantec Security Information Manager 4.8 Release Notes

Symantec Data Center Security: Server Advanced v6.0. Agent Guide

Symantec Event Collector 3.6 for Blue Coat Proxy Quick Reference

Symantec Protection Center Enterprise 3.0. Release Notes

Symantec NetBackup Vault Operator's Guide

Symantec Response Assessment module Installation Guide. Version 9.0

Symantec Virtual Machine Management 7.1 User Guide

Symantec Enterprise Vault Technical Note

Symantec Protection Engine for Cloud Services 7.0 Release Notes

Symantec Endpoint Protection Shared Insight Cache User Guide

Symantec Critical System Protection Agent Guide

Backup Exec Cloud Storage for Nirvanix Installation Guide. Release 2.0

Symantec Mobile Management 7.2 MR1Quick-start Guide

Symantec NetBackup for Microsoft SharePoint Server Administrator s Guide

Symantec ApplicationHA agent for SharePoint Server 2010 Configuration Guide

Veritas Operations Manager Release Notes. 3.0 Rolling Patch 1

Altiris Patch Management Solution for Linux 7.1 SP2 from Symantec User Guide

Symantec NetBackup Backup, Archive, and Restore Getting Started Guide. Release 7.5

Symantec Event Collector 4.3 for SNARE for Windows Quick Reference

Symantec Security Information Manager 4.6 Administrator's Guide

Symantec NetBackup OpenStorage Solutions Guide for Disk

Symantec ApplicationHA agent for Microsoft Exchange 2010 Configuration Guide

Encryption. Administrator Guide

Symantec Enterprise Security Manager Modules. Release Notes

Symantec System Recovery 2011 Management Solution Administrator's Guide

PGP Desktop Version 10.2 for Mac OS X Maintenance Pack Release Notes

Symantec Security Information Manager 4.5 Administrator's Guide

Altiris IT Analytics Solution 7.1 SP1 from Symantec User Guide

Symantec Management Platform Installation Guide. Version 7.0

Recovering Encrypted Disks Using Windows Preinstallation Environment. Technical Note

Configuring Symantec AntiVirus for Hitachi High-performance NAS Platform, powered by BlueArc

Symantec Event Collector 4.3 for Cisco PIX Quick Reference

Symantec ApplicationHA agent for Internet Information Services Configuration Guide

Symantec NetBackup for Microsoft SharePoint Server Administrator s Guide

PGP CAPS Activation Package

Symantec Mobile Security Manager Administration Guide

Symantec AntiVirus for Network Attached Storage Integration Guide

Symantec Endpoint Protection Integration Component 7.5 Release Notes

Veritas Operations Manager Advanced 5.0 HSCL Pack 1 Release Notes

Symantec Security Information Manager 4.5 Reporting Guide

Veritas Storage Foundation and High Availability Solutions Getting Started Guide

Symantec Security Information Manager 4.5 Installation Guide

Symantec Protection for SharePoint Servers Implementation Guide

Symantec Enterprise Vault

Symantec NetBackup Clustered Master Server Administrator's Guide

Altiris Asset Management Suite 7.1 SP2 from Symantec User Guide

Symantec ApplicationHA Agent for Microsoft Internet Information Services (IIS) Configuration Guide

Veritas Storage Foundation Scalable File Server Replication Guide 5.5

Symantec NetBackup for Lotus Notes Administrator's Guide

PGP Command Line Version 10.3 Release Notes

Altiris Monitor Solution for Servers 7.5 from Symantec User Guide

PGP Desktop Version 10.2 for Windows Maintenance Pack Release Notes

Altiris Patch Management Solution for Windows 7.1 SP2 from Symantec User Guide

Symantec Secure Proxy Administration Guide

Symantec Storage Foundation and High Availability Solutions Microsoft Clustering Solutions Guide for Microsoft SQL Server

PGP Command Line Version 10.2 Release Notes

Veritas Cluster Server Database Agent for Microsoft SQL Configuration Guide

Altiris Asset Management Suite 7.1 from Symantec User Guide

Symantec Patch Management Solution for Windows 7.5 SP1 powered by Altiris User Guide

Veritas Cluster Server Library Management Pack Guide for Microsoft System Center Operations Manager 2007

Symantec NetBackup for DB2 Administrator's Guide

Symantec Encryption Desktop Version 10.3 for Windows Maintenance Pack Release Notes

Symantec bv-control for Microsoft Exchange 9.0 Getting Started Guide

Symantec Endpoint Protection Small Business Edition Client Guide

Symantec Enterprise Vault

Symantec Enterprise Vault

Configuring Symantec AntiVirus for NetApp Storage system

Patch Assessment Content Update Release Notes for CCS Version: Update

Veritas Storage Foundation and High Availability Solutions HA and Disaster Recovery Solutions Guide for Enterprise Vault

Symantec Enterprise Security Manager Modules for Microsoft SQL Server Databases User s Guide and Reference

Symantec Enterprise Vault. Upgrading to Enterprise Vault

Symantec Endpoint Protection and Symantec Network Access Control Client Guide

Symantec NetBackup for Enterprise Vault Agent Administrator's Guide

Symantec NetBackup Clustered Master Server Administrator's Guide

Veritas Dynamic Multi-Pathing for Windows Release Notes

Symantec AntiVirus Installation Guide

Altiris Monitor Solution for Servers 7.1 SP1from Symantec User Guide

Symantec Database Security and Audit 3100 Series Appliance. Getting Started Guide

Transcription:

Symantec Critical System Protection Configuration Monitoring Edition Release Notes

Symantec Critical System Protection Configuration Monitoring Edition Release Notes The software described in this book is furnished under a license agreement and may be used only in accordance with the terms of the agreement. Documentation version 5.2 Legal Notice Copyright 2007 Symantec Corporation. All rights reserved. Symantec, the Symantec Logo, and LiveUpdate are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners. The product described in this document is distributed under licenses restricting its use, copying, distribution, and decompilation/reverse engineering. No part of this document may be reproduced in any form by any means without prior written authorization of Symantec Corporation and its licensors, if any. THE DOCUMENTATION IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON- INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. SYMANTEC CORPORATION SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE. The Licensed Software and Documentation are deemed to be commercial computer software as defined in FAR 12.212 and subject to restricted rights as defined in FAR Section 52.227-19 "Commercial Computer Software - Restricted Rights" and DFARS 227.7202, "Rights in Commercial Computer Software or Commercial Computer Software Documentation," as applicable, and any successor regulations. Any use, modification, reproduction release, performance, display or disclosure of the Licensed Software and Documentation by the U.S. Government shall be solely in accordance with the terms of this Agreement. Symantec Corporation 20330 Stevens Creek Blvd. Cupertino, CA 95014 http://www.symantec.com

Technical support Symantec Technical Support maintains support centers globally. Technical Support s primary role is to respond to specific queries about product feature and function. The Technical Support group also authors content for our online Knowledge Base. The Technical Support group works collaboratively with the other functional areas within Symantec to answer your questions in a timely fashion. For example, the Technical Support group works with Product Engineering and Symantec Security Response to provide alerting services and virus definition updates. Symantec s maintenance offerings include the following: A range of support options that give you the flexibility to select the right amount of service for any size organization A telephone and web-based support that provides rapid response and up-tothe-minute information Upgrade assurance that delivers automatic software upgrade protection Global support that is available 24 hours a day, 7 days a week Advanced features, including Account Management Services For information about Symantec s Maintenance Programs, you can visit our Web site at the following URL: www.symantec.com/techsupp/ Contacting Technical Support Customers with a current maintenance agreement may access Technical Support information at the following URL: www.symantec.com/techsupp/ Before contacting Technical Support, make sure you have satisfied the system requirements that are listed in your product documentation. Also, you should be at the computer on which the problem occurred, in case it is necessary to recreate the problem. When you contact Technical Support, please have the following information available: Product release level Hardware information Available memory, disk space, and NIC information Operating system

Version and patch level Network topology Router, gateway, and IP address information Problem description: Error messages and log files Troubleshooting that was performed before contacting Symantec Recent software configuration changes and network changes Licensing and registration Customer service If your Symantec product requires registration or a license key, access our technical support Web page at the following URL: www.symantec.com/techsupp/ Customer service information is available at the following URL: www.symantec.com/techsupp/ Customer Service is available to assist with the following types of issues: Questions regarding product licensing or serialization Product registration updates such as address or name changes General product information (features, language availability, local dealers) Latest information about product updates and upgrades Information about upgrade assurance and maintenance contracts Information about the Symantec Buying Programs Advice about Symantec's technical support options Nontechnical presales questions Maintenance agreement resources Issues that are related to CD-ROMs or manuals If you want to contact Symantec regarding an existing maintenance agreement, please contact the maintenance agreement administration team for your region as follows: Asia-Pacific and Japan: contractsadmin@symantec.com Europe, Middle-East, and Africa: semea@symantec.com North America and Latin America: supportsolutions@symantec.com

Additional enterprise services Symantec offers a comprehensive set of services that allow you to maximize your investment in Symantec products and to develop your knowledge, expertise, and global insight, which enable you to manage your business risks proactively. Additional services that are available include the following: Symantec Early Warning Solutions Managed Security Services Consulting services Educational Services These solutions provide early warning of cyber attacks, comprehensive threat analysis, and countermeasures to prevent attacks before they occur. These services remove the burden of managing and monitoring security devices and events, ensuring rapid response to real threats. Symantec Consulting Services provide on-site technical expertise from Symantec and its trusted partners. Symantec Consulting Services offer a variety of prepackaged and customizable options that include assessment, design, implementation, monitoring and management capabilities, each focused on establishing and maintaining the integrity and availability of your IT resources. These services provide a full array of technical training, security education, security certification, and awareness communication programs. To access more information about Enterprise Services, please visit our Web site at the following URL: www.symantec.com Select your country or language from the site index.

Contents Technical support Chapter 1 Introduction About Symantec Critical System Protection Configuration Monitoring Edition 9 About the licensed Symantec Critical System Protection content... 9 About the unlicensed Symantec Critical System Protection content... 11

8 Contents

Chapter 1 Introduction This chapter includes the following topics: About Symantec Critical System Protection Configuration Monitoring Edition About the licensed Symantec Critical System Protection content About the unlicensed Symantec Critical System Protection content About Symantec Critical System Protection Configuration Monitoring Edition Symantec Critical System Protection Configuration Monitoring Edition is a host intrusion detection-only version of Symantec Critical System Protection. Symantec Critical System Protection Configuration Monitoring Edition monitors the files and registry settings of a host system to identify changes in files, registry settings, and configurations. This monitoring complements traditional compliance auditing by providing near real-time identification of changes to key files and applications. About the licensed Symantec Critical System Protection content Release 5.2 includes licensed Symantec Critical System Protection content. Your use of Symantec Critical System Protection is limited to the following: File and registry monitoring features, collectors, and detection policies Agent status monitoring features and detection policies, to monitor file and registry changes

10 Introduction About the licensed Symantec Critical System Protection content Symantec Critical System Protection authoring environment, to author file and registry rules Symantec Critical System Protection Null prevention policy Management console Monitors page, Alerts page, Reports page, and Admin page Agent event viewer tool, to view recent events reported by an agent Table 1-1 lists the Symantec Critical System Protection detection policies that you are allowed to use. Table 1-1 Detection policies included in licensed content Operating system Microsoft Windows UNIX Detection policies You are allowed to use the following Windows detection policies: CSP_Agent_Diagnostics CSP_Agent_Status CSP_Server_Monitor Global_Watch_Policy Host_IDS_File_Tampering Malware MS_IIS_Security_Configuration MS_IIS_Vulnerable_CGI_Scripts Network_Comm_Configuration SANS Spyware System_AutoRun_Configuration System_Hardening System_Security_Configuration System_Shares_Configuration System_StartStop_Options USB_Device_Activity Windows_Template_Policy (File Watch, Registry Watch, and Generic rules) You are allowed to use the following UNIX detection policies: CSP_Agent_Diagnostics CSP_Agent_Status Host_IDS_File_Tampering Template_Policy (File Watch and Generic rules)

Introduction About the unlicensed Symantec Critical System Protection content 11 Table 1-1 Detection policies included in licensed content Operating system OS-specific Detection policies You are allowed to use the following OS-specific detection policies: Apache_Vulnerable_CGI_Scripts SANS A version of each policy is provided for agent computers that run the following operating systems: Sun Solaris Red Hat Enterprise Linux SUSE Linux Enterprise IBM AIX Hewlett-Packard HP-UX Hewlett-Packard Tru64 UNIX About the unlicensed Symantec Critical System Protection content Release 5.2 includes unlicensed Symantec Critical System Protection content. You are not allowed to use the following Symantec Critical System Protection content: Log monitoring features, including all log types such as Windows event log, Syslog, C2 log, and text log Prevention features Prevention and detection policies not specifically listed in the section on licensed Symantec Critical System Protection content See About the licensed Symantec Critical System Protection content on page 9. Use of these features and policies requires licensing of the Symantec Critical System Protection Server Edition for each system on which a prevention policy is enforced.

12 Introduction About the unlicensed Symantec Critical System Protection content