Version Affected: All
Overview
This article defines the IP Intelligence fields SecureAuth's Threat Service can return, and the Threat Type and Threat Category values that appear in a realm's logs to further classify a detected threat.
IP Intelligence Fields
- AE.IP.threatType: identifies the classification of the attack.
- AE.IP.threatCategory: identifies the attacker method.
- AE.IP.geoContinent: the continent of the IP address's location — Africa, Antarctica, Asia, Australia, Europe, North America, Oceania (Melanesia, Micronesia, Polynesia), or South America.
- AE.IP.geoCountry: the full country name, used within the ISO-3166 Alpha-2 code system.
- AE.IP.geoCountryCode: the International Organization for Standardization's 2-letter code for the country, as defined in ISO-3166.
- AE.IP.geoCountryCF: Country Confidence Factor, from 0 (null) to 99, reflecting a relative measure of certainty that the user is in the identified country. The higher the value, the greater the likelihood the user is in the assigned country.
- AE.IP.geoRegion: directional region information (for example, "northwest") for some countries, or specific regional information (for example, "northern_ireland") for others. Currently available for the U.S., U.K., Brazil, Denmark, France, Philippines, Belgium, Burkina Faso, Equatorial Guinea, Greece, Guinea, Indonesia, Ireland, Italy, Malawi, Marshall Islands, New Zealand, Slovenia, Spain, Sri Lanka, and Uganda.
- AE.IP.geoState: the state or province (first-level administrative division) in countries where they exist. IP Intelligence uses the localized spelling for state values — for example, the state of Tuscany in Italy is returned as toscana.
- AE.IP.geoStateCode: the abbreviated code identifying a state or province.
- AE.IP.geoStateCF: State Confidence Factor, from 0 (null) to 99, reflecting a relative measure of certainty that the user is in the identified state. The higher the value, the greater the likelihood the user is in the assigned state.
- AE.IP.geoCity: the city, recognizing more than 150,000 distinct international locations. IP Intelligence uses the localized spelling for city values — for example, the city of Rome in Italy is returned as roma.
- AE.IP.geoCityCF: City Confidence Factor, from 0 (null) to 99, reflecting a relative measure of certainty that the user is in the identified city. The higher the value, the greater the likelihood the user is in the assigned city.
- AE.IP.geoPostalCode: the postal code assigned to the corresponding city, derived from the city field where an explicit code isn't available. Provided for most countries.
- AE.IP.geoAreaCode: the phone number prefix assigned to the corresponding city, available in the U.S., Canada, and selectively elsewhere. Does not include the telephone country code.
- AE.IP.geoTimeZone: the time zone as a +/- offset from Greenwich Mean Time (GMT), expressed as a floating point number between -11 and 13. Derived from the city field if known, otherwise from the country field; if the city is unassigned and the country spans multiple time zones, a value of 999 is returned.
- AE.IP.geoLatitude: latitude of the identified location, expressed as a floating point number from -90 to 90 (positive is North, negative is South), derived from the city or postal code.
- AE.IP.geoLongitude: longitude of the identified location, expressed as a floating point number from -180 to 180 (positive is East, negative is West), derived from the city or postal code.
- AE.IP.dma: Defined Market Area code, assigned to U.S. geographical regions that typically receive similar media (radio, television, newspapers, and the Internet). Based on Nielsen's market codes with parity to Google's metropolitan area codes; adjacent cities such as San Francisco, San Jose, and Oakland can share the same DMA.
- AE.IP.msa: Metropolitan Statistical Area code, representing the geographical boundaries of U.S. counties or towns using Core-Based Statistical Areas (CBSAs) defined by the U.S. Office of Management and Budget (OMB) from U.S. Census Bureau data.
- AE.IP.connectionType: how the user connects to the Internet — fiber optic, leased line, high-speed/broadband, frame relay, DSL, cable modem, Integrated Services Digital Network, dial-up modem, fixed wireless, cellular, or unknown.
- AE.IP.lineSpeed: connection speed to the Internet — high, medium, or low — as determined by the Connection Type.
- AE.IP.ipRoutingType: how the connection is routed through the Internet, used to gauge how close the user is to the public IP address. For example, a fixed connection is likely very close to the connection; a regional proxy is probably in the same country; a satellite connection could be anywhere.
- AE.IP.geoAsn: Autonomous System Number (ASN), a globally unique number assigned to a group of networks administered by a single entity (such as a Network Service Provider or large organization). ASNs manage data routing via the Border Gateway Protocol (BGP); returned in 32-bit integer format.
- AE.IP.sld: Second-Level Domain, the part of the domain name preceding the top-level domain — for example, "companyname" in www.companyname.com.
- AE.IP.tld: Top-Level Domain, the most general part of the domain name in a web address — for example, com, net, edu, mil, or a country code such as jp or fr.
- AE.IP.organization: the Registering Organization responsible for the actions and content associated with a block of IP addresses (corporate, government, educational, or an ISP), as distinct from the carrier, which routes traffic for the network blocks.
- AE.IP.carrier: the organization that owns the ASN and is responsible for traffic on the Autonomous System (AS) it identifies. There are more than 27,000 active ASNs but fewer carriers, since a single carrier often manages several ASNs.
- AE.IP.anonymizer_status: a status assigned to an IP address detected as a proxy, indicating it may be associated with an anonymizing proxy, and how recently that proxy activity was confirmed.
- AE.IP.proxyLevel: the degree to which the proxy conceals the end user's originating IP address — transparent, anonymous, distorting, or elite.
- AE.IP.proxyType: the network or protocol the server uses to proxy the connection — HTTP, Tor, Web, or SOCKS.
- AE.IP.proxyLastDetected: the most recent date IP Intelligence confirmed the proxy was active or served as a private proxy.
- AE.IP.hostingFacility: whether the connection originated at a facility providing storage, computing, or telecommunication services — colocation, cloud computing, dedicated hosting, virtual private servers, or web hosting.
- AE.IP.RiskScore: a risk score based on IP address evaluation and threat intelligence data. Applies only to IP reputation log entries, and is also logged in the message element.
Threat Types
The following values appear only in the realm's logs, in the AE.IP.threatType field, and help further classify the type of threat detected.
- Anonymous Proxy (score 100, Extreme): authentication is coming from a server designed to hide or anonymize the actual source IP address.
- Attacker (score 99, Extreme): confirmed to host malicious content, function as a command-and-control (C2) server, or otherwise act as a source of malicious activity.
- Compromised (score 98, Extreme): confirmed to host malicious content due to compromise or abuse; the exact time and length of compromise is unknown unless disclosed in the report.
- Related (score 88, High): likely related to an attack, but potentially only partially confirmed — detailed by one or more methods such as passive DNS, geo-location, and connectivity detection.
- Victim (score 89, High): confirmed to have been victimized by malicious activity, where actors attempted or succeeded at compromise.
- Uncategorized (score 80, High): an uncategorized threat.
- No Threat Found (score 0, Low): not found in the threat aggregation platform.
Threat Categories
The following values appear only in the realm's logs, in the AE.IP.threatCategory field, and help further classify the type of threat detected.
- Anonymous Proxy (response value 0): authentication is coming from a server designed to hide or anonymize the actual source IP address.
- Cyber Espionage (response value 1): a global issue involving highly sophisticated nation-states and other actors targeting military, political, and commercial interests to gain decision advantage.
- Hacktivism (response value 2): activity ranging from nuisance-level to sophisticated, globally coordinated campaigns intended to negatively impact revenue or damage a brand.
- Enterprise (response value 3): threats specifically targeted at enterprises.
- Critical Infrastructure (response value 4): threats specifically targeted at critical infrastructure.
- Cyber Crime (response value 5): threats typically orchestrated by criminal elements for financial benefit.
- Vulnerability and Exploitation (response value 6): threats targeting known software vulnerabilities.
- No Threat Found (response value 999): not found in the threat aggregation platform.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.