9. Understanding Scores

Scores are used to determine the weight and importance that is applied to the threat. There are assorted weights that are applied based on criticality of the asset, importance of the data, and weight of the threat.

9.1. Working with Scores

There are a variety of activities that can be accomplished and worked with on the Scores, such as creating new Scores, defining the Rules, exporting, importing, moving, and deleting the scores and rules.

9.1.1. Viewing the Scores Dashboard

In order to view the Dashboard for the Scores, follow these steps:

  1. To access the Scores, Click on Analytics ‣ Scores.

score1

The Scores Management section shows the following information about the Scores:

  • Name

  • Enabled

  • Puablic

  • Action

  • Value

  • Group

9.1.2. Change the Group on the Scores Dashboard

When an analyst is working with the Scores for different customers or Groups, they can select a different Group by following these steps:

  1. To access the Scores Dashboard, Click on Analytics ‣ Scores.

score2

  1. On the top right side of the Scores Management window, Click on the Group link. (In this example, the Group is (Root).)

score3

  1. The “Select Group” window opens.

score4

  1. Click on the desired group.

  2. CLick on the OK button and the selected Group is changed on the Scores Management window. The information displayed reflects the data in the selected Group.

9.2. Managing Scores

There are a variety of activities that can be performed on the Scores, including defining new Scores, exporting and importing data into and out of the Dashboard, and deleting the Scores. This section provides the steps to perform each of these functions.

9.2.1. Creating New Scores

If new Scores are needed, perform the following steps:

  1. To access the Scores Dashboard, Click on Analytics ‣ Scores.

score5

  1. Click on the Add button.

  2. The “Rules Manager” window opens in the Basic tab, as shown:

score6

  1. Enter the name of the new Score being created in the Name field.

  2. To activate the Score to be used, check the box next to Enabled

  3. To allow other authorized users in the Group to use the Score, click on the checkbox next to Public. To make the rule Private leave the checkbox next to Public unchecked.

  4. Click on the Action drop-down arrow and select either Add (+) or Subtract (-) to select the Action.

Adding ensures that when the specified activity meets the criteria for the rule, the value selected is added to the weight of the event.

Subtracting ensures that when the specified activity meets the criteria for the rule, the value selected is subtracted from the weight to decrease the value of the event.

score7

  1. Enter the value for the new Score. This identifies the quantity that is either added or subtracted from the weight of the event when the activity matches the rule set for this Score.

  2. Select the Group for the new Score.

score8

  1. The next step is to click on the Rules tab.

score9

  1. Click on the Add button.

score10

Select “Add(&)” to set an “Add Operator” to the Rule.

Select “Or(||)” to set an “Or Operator” to the Rule.

Select “Rule” to add a Rule.

Note

The top item should be an And. So your first choice should be a Rule.

  1. If you choose Add ‣ Rule. The “Rules Editor” window opens.

score11

  1. Click on the drop-down arrow for the Module Key, and select a Correlation Key or Function.

score12

Some of the options for correlation keys are:

  • HAWK ID

  • Alert Name

  • Alert Category

  • Resource Name

  • Bayesian Score

  • All event columns can be used. For a complete list see Available Event Columns in the Reference Guide .

In addition to column names there are fuctions as shown below:

  • Stream Counter

  • Distinct Stream Counter

  • RBLDNS Blacklist Lookup

  • Timestamp - Day of Week

  • Timestamp - Hour and Minute

  • Vulnerability Threshold Analysis

  • Inter-Column Comparison

  • Host Lookup List

  1. If a column name was chosen as a Correlation key. The next step is to select the Comparison operator, which are:

  • <= (Less than or equal to)

  • < (Less than)

  • = (Equal to)

  • != (Not equal to)

  • >= (Greater than or equal to)

  • > (Greater than)

  1. Once the Comparison is entered, a corresponding Value must be entered as well in the Value field.

score13

Note

Some Module Keys will have the option for Regex and Case Sensitive. When checking the Regex box the Value should be a Regular Expression. If Case Sensitive is checked the value will only match if the case is the same. Default value is case insensitive.

  1. If a function was used as a correlation key you will have to fill in each provided field for that specific function. In this example, using ‘Host Lookup List’

First, select a column that you will compare against.

Second, select a comparison, in this example ‘Equals To (=)’.

Last, Enter the location to the file to compare the column against.

score14

Note

Each function will have it’s specific filelds that will need to be filled out.

  1. When all the values are entered, click on the Ok button to add the new rule. To cancel adding the new Rule, Click on the Cancel button.

  2. When all rules have been entered, click on the Ok button to add the new Score. To cancel adding the new Score, Click on the Cancel button.

  3. When the new Score is added it is now displayed in the Scores Manager.

9.2.2. Updating Scores

The Scores can be updated at any time by following these steps:

  1. To access the Scores Dashboard, Click on Analytics ‣ Scores.

score15

  1. Double click on the score you want to change, to bring up the Rules Manager.

The Rules manager opens to display the defined values for the Rule.

score16

  1. Click on the fields to change the value for the Rule, as needed, on the Basic tab. This includes the following:

  • Name

  • Action

  • Value

  • Group

  1. Click on the Rules tab.

  2. Double-click on the desired Rule to update or click Add to add a new rule, or add a logical operator.

The “Rule Editor” window opens.

score17

  1. Select the desired values to change.

  2. Click on the OK button to save the changes or click on the Cancel button to cancel the changes.

  3. When all rules have been entered, click on the Ok button to save the Score. To cancel the changes to the Score, Click on the Cancel button.

  4. The changes are now updated.

9.2.3. Moving a Score or Scores to Another Group

The Scores can be moved to another Group at any time by following these steps:

  1. To access the Scores Dashboard, Click on Analytics ‣ Scores.

score18

  1. Click on the Score or Scores to move.

score19

  1. Click on Action ‣ Move.

  2. The “Select Group” window will open.

score20

  1. Select the group you want to move your score(s) to.

  2. Click OK button to save your changes.

9.2.4. Cloning Scores

The Scores can be cloned by doing the following:

  1. To access the Scores Dashboard, Click on Analytics ‣ Scores.

score21

  1. Click on the Score or Scores to clone.

score22

  1. Click on Action ‣ Clone.

  2. The notification dialog opens to indicate that the selected Score(s) is to be cloned.

score23

  1. Click the No button to cancel the clone operation. Click the Yes button to clone the Scores.

  2. The new score will show in the Score Dashboard with “-clone” at the end of the name.

9.2.5. Exporting Scores

The Scores can be exported at any time by following these steps:

  1. To access the Scores Dashboard, Click on Analytics ‣ Scores.

score24

  1. Select the score or scores you want to export.

score25

  1. Click on Action ‣ Export.

  2. The notification dialog opens to indicate that the selected Score(s) is being exported.

Note

Your browser may download the csv file to its default directory or may ask you for a location to download the file.

9.2.6. Importing Scores

The Scores can be imported at any time by following these steps.

  1. To access the Scores Dashboard, Click on Analytics ‣ Scores.

score26

  1. Navigate to the desired group to which you want the scores to be imported into.

  2. Click on Action ‣ Import.

  3. The “Choose File to Upload” window opens.

  4. Click on the desired file to import.

  5. Click on the “Open” button.

  6. The selected file is imported into the Scores.

9.2.7. Deleting a Score or Scores

If a Scores is no longer needed, it can be deleted at any time by following these steps:

  1. To access the Scores Dashboard, Click on Analytics ‣ Scores.

score27

  1. Select the score or scores you want to delete.

score28

  1. Click on Action ‣ Delete.

  2. The delete confirmation dialog opens to confirm that the correct Score or Scores to be deleted are selected. Click on ‘Yes’ to confirm. To cancel the delete, click on the ‘No’ button.

score29

9.3. Creating Custom Scores

For more information on how to create custom scores please see How To Create Custom Scores Section