Version 7.2
727
Mediant 500 MSBR
User's Manual
40. Configuring Malicious Signatures
40
Configuring Malicious Signatures
The Malicious Signature table lets you configure up to 30 Malicious Signature patterns.
Malicious Signatures are signature patterns that identify SIP user agents (UA) who perform
malicious attacks on SIP servers by SIP scanning. Malicious Signatures allow you to
protect SBC calls handled by the device from such malicious activities, thereby increasing
your SIP security. The Malicious Signature patterns identify specific scanning tools used by
attackers to search for SIP servers in the network. The feature identifies and protects
against SIP (Layer 5) threats by examining new inbound SIP dialog messages. Once the
device identifies an attack based on the configured malicious signature pattern, it marks
the SIP message as invalid and discards it or alternatively, rejects it with a SIP response
(by default, 400), configured in the Message Policies table. Protection applies only to new
dialogs (e.g., INVITE and REGISTER messages) and unauthenticated dialogs.
Malicious signatures can also be used with the Intrusion Detection System (IDS) feature
(see Configuring IDS Policies on page 156). You can configure an IDS Policy that is
activated if the device detects a malicious signature (when the 'Reason' parameter is
configured to
Dialog establishment failure
).
Malicious signature patterns are typically based on the value of SIP User-Agent headers,
which attackers use as their identification string (e.g., "User-Agent: VaxSIPUserAgent").
However, you can configure signature patterns based on any SIP header. To configure
signature patterns, use the same syntax as that used for configuring Conditions in the
Message Manipulations table (see Configuring SIP Message Manipulation on page 381).
Below are configured signature patterns based on the User-Agent header:
Malicious signature for the VaxSIPUserAgent malicious UA:
header.user-agent.content prefix 'VaxSIPUserAgent'
Malicious signature for the scanning tool "sip-scan":
header.user-agent.content prefix 'sip-scan'
By default, the table provides preconfigured malicious signatures of known, common
attackers.
Note:
•
Malicious Signatures do not apply to the following:
√
Calls from IP Groups where Classification is by Proxy Set.
√
In-dialog SIP sessions (e.g., refresh REGISTER requests and re-INVITEs).
√
Calls from users that are registered with the device.
•
If you delete all the entries in the table, when you next reset the device, the table
is populated again with all the default signatures.
You can export / import Malicious Signatures in CSV file format to / from a remote server
through HTTP, HTTPS, or TFTP. To do this, use the following CLI commands:
(config-voip)# sbc malicious-signature-database <export-csv-to |
import-csv-from> <URL>
To apply malicious signatures to calls, you need to enable the use of malicious signatures
for a Message Policy and then assign the Message Policy to the SIP Interface associated
with the calls (i.e., IP Group). To configure Message Policies, see Configuring SIP
Message Policy Rules.
The following procedure describes how to configure Malicious Signatures through the Web
interface. You can also configure it through ini file (MaliciousSignatureDB) or CLI (configure
voip > sbc malicious-signature-database).
Summary of Contents for Mediant 500 MSBR
Page 2: ......
Page 33: ...Part I Getting Started with Initial Connectivity ...
Page 34: ......
Page 36: ...User s Manual 36 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 40: ...User s Manual 40 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 45: ...Part II Management Tools ...
Page 46: ......
Page 48: ...User s Manual 48 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 115: ...Part III General System Settings ...
Page 116: ......
Page 132: ...User s Manual 132 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 137: ...Part IV General VoIP Configuration ...
Page 138: ......
Page 290: ...User s Manual 290 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 306: ...User s Manual 306 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 380: ...User s Manual 380 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 454: ...User s Manual 454 Document LTRT 10375 Mediant 500 MSBR This page is intentionallty left blank ...
Page 455: ...Part V Gateway Application ...
Page 456: ......
Page 460: ...User s Manual 460 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 484: ...User s Manual 484 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 494: ...User s Manual 494 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 625: ...Part VI Session Border Controller Application ...
Page 626: ......
Page 654: ...User s Manual 654 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 656: ...User s Manual 656 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 741: ...Part VII Cloud Resilience Package ...
Page 742: ......
Page 751: ...Part VIII Data Router Configuration ...
Page 752: ......
Page 753: ......
Page 754: ......
Page 756: ...User s Manual 756 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 757: ...Part IX Maintenance ...
Page 758: ......
Page 834: ...User s Manual 834 Document LTRT 10375 Mediant 500 MSBR This page is intetnionaly left blank ...
Page 837: ...Part X Status Performance Monitoring and Reporting ...
Page 838: ......
Page 848: ...User s Manual 848 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 852: ...User s Manual 852 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 854: ...User s Manual 854 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 878: ...User s Manual 878 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 880: ...User s Manual 880 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 926: ...User s Manual 926 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 927: ...Part XI Diagnostics ...
Page 928: ......
Page 950: ...User s Manual 950 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 954: ...User s Manual 954 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 956: ...User s Manual 956 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 958: ...User s Manual 958 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 974: ...User s Manual 974 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 976: ...User s Manual 976 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 977: ...Part XII Appendix ...
Page 978: ......
Page 982: ...User s Manual 982 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...