Viewing Rule Details Configure the UMS Driver

Managing Policies, Rules, and Conditions 10-33 To specify preconditions for the rule:

1. Navigate to the Rule Details page.

a. In the Navigation tree, select Rules. The Rules Search page is displayed.

b. Search for the rule in which you want to specify preconditions for.

c. In the Search Results table, click the name of the rule. The Rule Details page

for that rule is displayed.

2. In the Rule Details page, click the Preconditions tab.

3. Excluded User Group

: In the Excluded User Group field, select the User ID group you do not want the policy to applied to.

4. Device Risk Gradient

: Device fingerprinting is a mechanism to recognize the device a customer typically uses to log in. Identification is based on combinations of the Device ID attributes, secure cookie, flash object, user agent string, browser characteristics, device hardware configuration, network characteristics, geolocation and historical context. Different use cases and exceptions are taken into account and help to define the device risk gradient. The device risk gradient specifies the certainty of the device being identified. It is standard in almost all rules as a precondition. The score ranges to specify the amount of device identification risk are: ■ 400 and lower - low risk ■ 401-700 - moderate risk ■ 701 and higher - high risk For example, a device risk gradient of 0 is an exact match whereas a device gradient of 500 is a similar device, and a score of 1000 a different device.

5. Country Confidence Factor

, State Confidence Factor, and City Confidence Factor : The IP location vendor can assign a confidence level to each of the three elements: city, state, and country. This confidence factor is based on IP geolocation information. The higher the value, the higher the level of confidence from Quova that the mapping of the location is correct. If you want the rule you are creating to be dependent on IP location identification accuracy, specify the amount of geolocation accuracy with which you want to run the rule. For example, if the range is 60 to 100, you may specify for the rule to run only if the IP location is greater than 60 positive.

10.21.3 Specifying the Results for a Rule

Results are the responses, such as the activation of an action and message, when a rule is triggered. For example, action event activated and alert message activated. As part of the process, specify: ■ Rule score and weight value ■ Actions ■ Alerts To specify the results for if the rule triggers, follow these steps: 10-34 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

1. Navigate to the Rule Details page if you are not on the Rule Details page of the

rule you want.

a. In the Navigation tree, select Rules. The Rules Search page is displayed.

b. Search for the rule for which you want to specify the results.

c. In the Search Results table, click the name of the rule. The Rule Details page

for that rule is displayed.

2. In the Rule Details page, click the Results tab.

3. Enter a rule score and weight value. You can change the weight value for a rule to instruct OAAM Admin to give more or less value to the total score. By default the score is 1000 and the weight is 100.

4. In the Actions Group list, select the actions you want triggered by this rule, if

actions are required. By default, an Actions Group is not selected. 5. In the Alerts Group list, select the alerts you want sent if this rule is triggered. By default, an Alerts Group is not selected.

6. Click Apply to save the modified rule details.

The rules engine takes the information you specify for the rule and information specified in other rules in the policy and returns rule results to the policy. All the policies in the policy set results in multiple actions and multiple scores and multiple alerts. All these are propagated to the checkpoint. The score, the weight, and so on result in one final score, one final action, and a couple of alerts. An example of a final action is Block. An example action list is Block, Challenge, Background Check and an example score is 800.

10.22 Working with Scores and Weights

For information about the processing of policies to come up with scores, actions, and alerts, see Chapter 14, Using the Scoring Engine.

10.23 ActivateDisable Rule

To activatedisable a rule:

1. In the Summary tab of Rule Details, select Active or Disable for Status.

Table 10–10 Results Tab Field Description Score Integer value from 0 to 1000. The minimum and maximum scores for the Score are defined as properties. Weight Integer value from 0 to 100 Action Group Group of actions. An action group indicates all the actions that must occur when the rule is triggered. Alert Group Group of graded messages that are used as results within rules so that when a rule is triggered all of the alerts within the groups are activated.