show analysis summary by

Prev Next

To display the details about the malware analysis summary based on the source IP address, destination IP address, MD5 checksum, or URL, use the show analysis summary by command in configuration mode.

This command searches for the details in the event results table based on the event type (os-change-anomaly, checksum-match, malware-callback, and so on). You can view malicious and nonmalicious objects and URLs from a specified source IP address or destination address. A message is displayed if no data is found based on your search results.

When you enter this command on a Central Management System appliance, the appliance displays details about the malware analysis summary on all connected Network Security appliances based on your search queries.

Syntax

show analysis summary by source <IP address> and destination <IP address>

show analysis summary by source <IP address> or destination <IP address>

show analysis summary by source <IP address>

show analysis summary by destination <IP address>

show analysis summary by URL <string>

show analysis summary by checksum <value>

Parameters

source <IP address> and destination <IP address>

Displays the search results from a source IP address and destination IP address.

source <IP address> or destination <IP address>

Displays the search results from a source IP address or destination IP address.

source <IP address>

Displays the search results from a source IP address.

destination <IP address>

Displays the search results from a destination IP address.

URL <string>

Displays the search results for a particular URL.

checksum <value>

Displays the search results for an object of the specified MD5 checksum.

Example

The following example verifies the search results for rmalicious and nonmalicious objects and URLs from a particular source IP address and destination IP address:

hostname (config) # show analysis summary by source 172.16.8.87 and destination 172.16.1.11
Source IP   Destination IP  Checksum                        Occurred Time (UTC)  Is Malicious   URL
---------------------------------------------------------------------------------------------------
172.16.8.87 172.16.1.11     707dbb57d9d67214961eed30d48e6570 2014-10-01 04:36:55 No 172.16.1.11/~ywang/poc.doc

When you enter this command on a Central Management System appliance, the following example verifies the details about the malware analysis summary on all connected Network Security appliances based on your search queries:

hostname (config) # show analysis summary by checksum 65af4678c1f68dd2d72213087a55160d
Appliance  Source IP   Destination IP  Checksum             Occurred Time (UTC)  Is Malicious   URL
---------------------------------------------------------------------------------------------------
WEB39   172.19.97.222 171.64.11.133     65af4678c1f68dd2d72213087a55160d 2014-10-08 15:14:30 No itwsus2.stanford.edu/Content/BD/E9B68C5E63ACB786A05B53B4332465DE0EBCEEBD.exe

User role

Admin, Analyst, Monitor, Operator

Supported appliances

Network Security: Release 7.5.0

Central Management System: Release 7.5.0