Chapter 31 IDP
ZyWALL USG 2000 User’s Guide
500
31.6.3 IDP Service Groups
An IDP service group is a set of related packet inspection signatures.
The following figure shows the WEB_PHP service group that contains signatures
related to attacks on web servers using PHP exploits. PHP (PHP: Hypertext
Preprocessor) is a server-side HTML embedded scripting language that allows web
developers to build dynamic websites.
Buffer Overflow
A buffer overflow occurs when a program or process tries to store
more data in a buffer (temporary data storage area) than it was
intended to hold. The excess information can overflow into adjacent
buffers, corrupting or overwriting the valid data held in them.
Intruders could run codes in the overflow buffer region to obtain
control of the system, install a backdoor or use the victim to launch
attacks on other devices.
Virus/Worm
A computer virus is a small program designed to corrupt and/or alter
the operation of other legitimate programs. A worm is a program that
is designed to copy itself from one computer to another on a network.
A worm’s uncontrolled replication consumes system resources, thus
slowing or stopping other tasks.
Backdoor/Trojan
A backdoor (also called a trapdoor) is hidden software or a hardware
mechanism that can be triggered to gain access to a program, online
service or an entire computer system. A Trojan horse is a harmful
program that is hidden inside apparently harmless programs or data.
Although a virus, a worm and a Trojan are different types of attacks,
they can be blended into one attack. For example, W32/Blaster and
W32/Sasser are blended attacks that feature a combination of a
worm and a Trojan.
Access Control
Access control refers to procedures and controls that limit or detect
access. Access control attacks try to bypass validation checks in order
to access network resources such as servers, directories, and files.
Web Attack
Web attacks refer to attacks on web servers such as IIS (Internet
Information Services).
Table 148
Policy Types (continued)
POLICY TYPE
DESCRIPTION
Table 149
IDP Service Groups
WEB_PHP WEB_MISC
WEB_IIS
WEB_FRONTPAGE
WEB_CGI WEB_ATTACKS
TFTP
TELNET
SQL SNMP
SMTP RSERVICES
RPC POP3
POP2 P2P
ORACLE NNTP
NETBIOS MYSQL
MISC_EXPLOIT MISC_DDOS
MISC_BACKDOOR MISC
IMAP IM
ICMP
FTP
FINGER DNS
Summary of Contents for ZyXEL ZyWALL USG-1000
Page 2: ......
Page 30: ...30 ...
Page 58: ...Chapter 3 Web Configurator ZyWALL USG 2000 User s Guide 58 ...
Page 84: ...Chapter 4 Wizard Setup ZyWALL USG 2000 User s Guide 84 ...
Page 136: ...Chapter 6 Tutorials ZyWALL USG 2000 User s Guide 136 ...
Page 166: ...Chapter 9 Signature Update ZyWALL USG 2000 User s Guide 166 ...
Page 168: ...168 ...
Page 234: ...Chapter 11 Trunks ZyWALL USG 2000 User s Guide 234 ...
Page 248: ...Chapter 12 Policy and Static Routes ZyWALL USG 2000 User s Guide 248 ...
Page 272: ...Chapter 15 DDNS ZyWALL USG 2000 User s Guide 272 ...
Page 287: ...Chapter 16 Virtual Servers ZyWALL USG 2000 User s Guide 287 ...
Page 288: ...Chapter 16 Virtual Servers ZyWALL USG 2000 User s Guide 288 ...
Page 307: ...307 PART III Firewall Firewall 309 ...
Page 308: ...308 ...
Page 326: ...Chapter 20 Firewall ZyWALL USG 2000 User s Guide 326 ...
Page 328: ...328 ...
Page 370: ...Chapter 21 IPSec VPN ZyWALL USG 2000 User s Guide 370 ...
Page 392: ...Chapter 23 SSL User Screens ZyWALL USG 2000 User s Guide 392 ...
Page 394: ...Chapter 24 SSL User Application Screens ZyWALL USG 2000 User s Guide 394 ...
Page 402: ...Chapter 25 SSL User File Sharing ZyWALL USG 2000 User s Guide 402 ...
Page 412: ...Chapter 27 L2TP VPN ZyWALL USG 2000 User s Guide 412 ...
Page 440: ...Chapter 28 L2TP VPN Example ZyWALL USG 2000 User s Guide 440 ...
Page 441: ...441 PART V Application Patrol Application Patrol 443 ...
Page 442: ...442 ...
Page 470: ...470 ...
Page 531: ...Chapter 32 ADP ZyWALL USG 2000 User s Guide 531 Figure 371 Profiles Protocol Anomaly ...
Page 540: ...Chapter 32 ADP ZyWALL USG 2000 User s Guide 540 ...
Page 566: ...Chapter 33 Content Filtering ZyWALL USG 2000 User s Guide 566 ...
Page 574: ...Chapter 34 Content Filter Reports ZyWALL USG 2000 User s Guide 574 ...
Page 593: ...593 PART VII Device HA Device HA 595 ...
Page 594: ...594 ...
Page 614: ...614 ...
Page 636: ...Chapter 38 Addresses ZyWALL USG 2000 User s Guide 636 ...
Page 660: ...Chapter 41 AAA Server ZyWALL USG 2000 User s Guide 660 ...
Page 686: ...Chapter 43 Certificates ZyWALL USG 2000 User s Guide 686 ...
Page 698: ...Chapter 45 SSL Application ZyWALL USG 2000 User s Guide 698 ...
Page 699: ...699 PART IX System System 701 ...
Page 700: ...700 ...
Page 750: ...750 ...
Page 776: ...Chapter 48 Logs ZyWALL USG 2000 User s Guide 776 ...
Page 794: ...Chapter 49 Reports ZyWALL USG 2000 User s Guide 794 ...
Page 796: ...Chapter 50 Diagnostics ZyWALL USG 2000 User s Guide 796 ...
Page 798: ...Chapter 51 Reboot ZyWALL USG 2000 User s Guide 798 ...
Page 812: ...Chapter 53 Product Specifications ZyWALL USG 2000 User s Guide 812 ...
Page 814: ...814 ...
Page 874: ...Appendix A Log Descriptions ZyWALL USG 2000 User s Guide 874 ...
Page 956: ...Appendix E Open Software Announcements ZyWALL USG 2000 User s Guide 956 ...
Page 960: ...Appendix F Legal Information ZyWALL USG 2000 User s Guide 960 ...