Configuring a Protocol Anomaly Attack Object
A protocol anomaly attack object locates unknown or sophisticated attacks that violate
protocol specifications (RFCs and common RFC extensions). You cannot create new
protocol anomalies, but you can configure a custom attack object that controls how the
security device handles a predefined protocol anomaly when detected.
NOTE:
Protocol anomaly attack objects are supported by IDP-capable
security devices only, such as the ISG2000 or ISG1000 running ScreenOS
5.3 or later IDP1.
To configure a custom protocol anomaly attack object, you must:
•
Configure the false positive setting—For details, see “Configuring Attack Detection
Properties” on page 352.
•
Select a predefined protocol anomaly—Select the protocol anomaly you want to use
for this attack object. The list of available predefined protocol anomalies depends on
the protocols supported by the target platform. For details, refer to the NSM Online
Help.
•
Configure the time-based settings—For details, see “Configuring Time Binding” on
page 351.
Configuring a Compound Attack Object
A compound attack object combines multiple signatures and protocol anomalies into a
single attack object, forcing traffic to match all combined signatures and anomalies
within the compound attack object before traffic is identified as an attack. By combining
and even specifying the order in which signatures or anomalies must match, you can be
very specific about the events that need to take place before the security device identifies
traffic as an attack.
NSM 2006.1 and later releases also support Boolean expressions for standalone IDP
signatures.
NOTE:
Compound attack objects are supported by IDP-capable security
devices only, such as the ISG series with Security Module or any of the
standalone IDP Sensors. ISG series devices do not support Boolean
expressions.
When configuring a custom compound attack object:
•
All members of the compound attack object must use the same service setting or
service binding, such as FTP, Telnet, YMSG, or TCP/80.
•
You can add protocol anomaly attack objects to a compound attack object.
359
Copyright © 2010, Juniper Networks, Inc.
Chapter 8: Configuring Objects
Содержание NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 236: ...Copyright 2010 Juniper Networks Inc 186 Network and Security Manager Administration Guide...
Страница 292: ...Copyright 2010 Juniper Networks Inc 242 Network and Security Manager Administration Guide...
Страница 314: ...Copyright 2010 Juniper Networks Inc 264 Network and Security Manager Administration Guide...
Страница 368: ...Copyright 2010 Juniper Networks Inc 318 Network and Security Manager Administration Guide...
Страница 370: ...Copyright 2010 Juniper Networks Inc 320 Network and Security Manager Administration Guide...
Страница 484: ...Copyright 2010 Juniper Networks Inc 434 Network and Security Manager Administration Guide...
Страница 584: ...Copyright 2010 Juniper Networks Inc 534 Network and Security Manager Administration Guide...
Страница 588: ...Copyright 2010 Juniper Networks Inc 538 Network and Security Manager Administration Guide...
Страница 600: ...Copyright 2010 Juniper Networks Inc 550 Network and Security Manager Administration Guide...
Страница 678: ...Copyright 2010 Juniper Networks Inc 628 Network and Security Manager Administration Guide...
Страница 694: ...Copyright 2010 Juniper Networks Inc 644 Network and Security Manager Administration Guide...
Страница 700: ...Copyright 2010 Juniper Networks Inc 650 Network and Security Manager Administration Guide...
Страница 706: ...Copyright 2010 Juniper Networks Inc 656 Network and Security Manager Administration Guide...
Страница 708: ...Copyright 2010 Juniper Networks Inc 658 Network and Security Manager Administration Guide...
Страница 758: ...Copyright 2010 Juniper Networks Inc 708 Network and Security Manager Administration Guide...
Страница 788: ...Copyright 2010 Juniper Networks Inc 738 Network and Security Manager Administration Guide...
Страница 882: ...Copyright 2010 Juniper Networks Inc 832 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 918: ...Copyright 2010 Juniper Networks Inc 868 Network and Security Manager Administration Guide...
Страница 920: ...Copyright 2010 Juniper Networks Inc 870 Network and Security Manager Administration Guide...
Страница 1005: ...PART 6 Index Index on page 957 955 Copyright 2010 Juniper Networks Inc...
Страница 1006: ...Copyright 2010 Juniper Networks Inc 956 Network and Security Manager Administration Guide...