information, attack pattern, and other important information. After you have configured
the object however, you use each object differently:
•
To use a custom DI attack object to protect your network, you must add the object to
a custom attack object group and then a DI Profile object, which you then select within
the Rule Options of a firewall rule. For information about creating a custom attack
object group, see “Creating Custom IDP Attack Groups” on page 357. For information
about creating a DI Profile object, see “Creating DI Profiles” on page 334.
•
To use a custom IDP attack object to protect your network, you can add the attack
object in an IDP rule.
NSM enables you to import custom attacks and custom attack groups from SRX Series
devices and display them as shared objects in Object Manager. You can also edit
custom attacks and custom attack groups using Object Manager and update the device
with these changes.
Using the Attack Object Wizard
To help you create custom attack objects, NSM UI uses a Custom Attack Object wizard
to guide you through each step. During the creation process, the wizard prompts you for:
•
Attack object information—You must supply an attack object name and configure the
target platforms that support the attack object. You can also create an attack
description, enter attack references, and set a severity for the attack object, if desired.
The following sections detail the general attack object information fields.
•
Attack Version information—After you have selected the target platforms, you must
supply information about the attack version, including the protocol and context used
to perpetrate the attack. when the attack is considered malicious, the direction and
flow of the attack, the signature pattern of the attack, and the values found in the
header section of the attack traffic.
To create a custom attack object, from the main navigation tree, select
Object Manager
> Attack Objects > DI Objects
or
IDP Objects
, then select the Custom Attacks tab. Click
the Add icon to display the custom attack object wizard.
Copying and Editing Predefined Attack Objects to Create Custom Attack Objects
You can also make a copy of a predefined attack object. This copy is a custom attack
object, which you can modify like any other custom object. The copy must have a different
name than the original, predefined attack object.
To create a custom version of a predefined attack object, open an existing predefined
attack object, and click the Edit button in the Attack Viewer. A new attack object with
the same parameters as the existing predefined attack object appears. The new object
has the same name as the previous object, but with “ -Copy” appended. After editing the
parameters that you want, click
OK
.
The following sections explain the attack object creation process; for instructions for
creating a custom attack object, see the
NSM Online Help
topic, “Creating Custom Attack
Objects.” The fields that can be modified are described below.
339
Copyright © 2010, Juniper Networks, Inc.
Chapter 8: Configuring Objects
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...