Problem: System-wide IP whitelisting ignores context (e.g., whitelisting the gateway router's ICMP pings also blinds the Web Router decoy).
Solution: implement sensor rules (e.g. suppression_rules.) The rules engine will check for a specific condition in the events reported from the sensor and will be able to do things such as muting the event, ignoring it, escalating it, or could even be a tool for a future implementation of Hub side correlation between events.
Problem: System-wide IP whitelisting ignores context (e.g., whitelisting the gateway router's ICMP pings also blinds the Web Router decoy).
Solution: implement sensor rules (e.g.
suppression_rules.) The rules engine will check for a specific condition in the events reported from the sensor and will be able to do things such as muting the event, ignoring it, escalating it, or could even be a tool for a future implementation of Hub side correlation between events.