SmartDefense Categories
Chapter 13: Using SmartDefense
301
Header Rejection
Some exploits are carried in standard HTTP headers with custom values (for example, in the Host header),
or in custom HTTP headers. You can protect against such exploits by rejecting HTTP requests that contain
specific headers and header values.
Table 78: Header Rejection Fields
In this field…
Do this…
Action
Specify what action to take when an HTTP header-based exploit is
detected, by selecting one of the following:
Block.
Block the attack.
None.
No action. This is the default.
Track
Specify whether to log HTTP header-based exploits, by selecting one of
the following:
Log.
Log the attack.
None.
Do not log the attack. This is the default.
HTTP header values
list
Select the HTTP header values to detect.
Worm Catcher
A worm is a self-replicating malware (malicious software) that propagates by actively sending itself to new
machines. Some worms propagate by using security vulnerabilities in the HTTP protocol.
Summary of Contents for IP60 - Security Appliance
Page 1: ...Part No N450000643 Rev 001 Published February 2008 Nokia IP60 Security Appliance User Guide ...
Page 4: ...4 Nokia IP60 Security Appliance User Guide ...
Page 10: ......
Page 12: ......
Page 38: ......
Page 58: ......
Page 108: ......
Page 268: ......
Page 482: ......