SRX IDP Full IDP Stateful Inspection 8 Detection mechanisms including Stateful Signatures and Protocol Anomalies Reassemble, normalize, eliminate ambi

Similar documents
Juniper Networks Corporate PowerPoint Template

SCREENOS NAT ScreenOS J-Series(JUNOS9.5 ) NAT ScreenOS J-Series(JUNOS9.5 ) NAT : Destination NAT Zone NAT Pool DIP IF NAT Pool Egress IF Loopback Grou

Dynamic VPN Dynamic VPN IPSec VPN PC SRX IPSec VPN SRX PC IPSec 2 Copyright 2010 Juniper Networks, Inc.

IPSEC-VPN IPsec(Security Architecture for Internet Protocol) IP SA(Security Association, ) SA IKE IKE 1 1 ISAKMP SA( ) IKE 2 2 IPSec SA( 1 ) IPs

Win XP SP3 Japanese Ed. NCP IPSec client Hub L3 SW SRX100 Policy base VPN fe-0/0/0 vlan.0 Win 2003 SVR /

ScreenOS 5.0 ScreenOS 5.0 Deep Inspection VLAN NetScreen-25/-50/-204/-208 HA NetScreen-25 HA Lite NetScreen-25 NetScreen-50) ALG(Application Layer Gat

Cisco ASA Firepower ASA Firepower

SRXシリーズおよびJシリーズのネットワークアドレス変換

Juniper Networks Corporate PowerPoint Template

Document

SRX License

Agenda IPv4 over IPv6 MAP MAP IPv4 over IPv6 MAP packet MAP Protocol MAP domain MAP domain ASAMAP ASAMAP 2

Cisco® ASA シリーズルーター向けDigiCert® 統合ガイド

ScreenOS Copyright (C) 2005 NOX Co., Ltd. All Rights Reserved. Version1.00

拠点/支社向けSRXシリーズおよびJシリーズのWebフィルタリング

snortの機能を使い尽くす & hogwashも使ってみる

Microsoft Word - D JP.docx

BRANCH SRX <2010Q3 > 2 Copyright 2010 Juniper Networks, Inc.

FW Migration Guide (Single)

IOS ゾーン ベースのポリシー ファイアウォールを使用した IOS ルータでの AnyConnect VPN クライアントの設定例

SRT/RTX/RT設定例集

fx-9860G Manager PLUS_J

<Documents Title Here>

Microsoft PowerPoint - TD_CGN.pptx

owners.book

2 BIG-IP 800 LTM v HF2 V LTM L L L IP GUI VLAN.

VMware View Persona Management

Cisco Umbrella Branch Cisco Umbrella Branch Cisco ISR Umbrella Branch

RTX830 取扱説明書

untitled

IP.dvi

契約№2020-XXXX

目次 1.rug について zmd の動作確認 rug からの情報の取得 rug コマンドの使用例 アップデート可能なパッケージの一覧を表示 パッケージを検索する 特定のパッケージをインストール / ア

I j

Lync Server 2010 Lync Server Topology Builder BIG-IP LTM Topology Builder IP Lync 2010 BIG IP BIG-IP VE Virtual Edition BIG-IP SSL/TLS BIG-IP Edge Web

Packet Tracer: 拡張 ACL の設定 : シナリオ 1 トポロジ アドレステーブル R1 デバイスインターフェイス IP アドレスサブネットマスクデフォルトゲートウェイ G0/ N/A G0/

00.目次_ope

初めてのBFD

設定例集_Rev.8.03, Rev.9.00, Rev.10.01対応

(Microsoft PowerPoint - 10.Firewall\220\335\222\350_rev1.6.pptx)

最も一般的な手法: ファイアウォールによってノード間の MPI 通信がブロックされた場合の対応方法

iPhone/iPad/Android(TM) とベリサイン アイデンティティプロテクション(VIP)エンタープライズゲートウェイとの組み合わせによるL2TP+IPsecのワンタイムパスワード設定例

IP... 2 IP... 2 IP... 2 IP... 2 VLAN... 3 IP ADD IP IPADDRESS... 5 DELETE IP... 7 PING SETIP SHOW IP IP CentreCOM FS9

untitled

GA-1190J

untitled

スライド 1

設定手順

Catalyst 3850 スイッチのセキュリティ ACL TCAM 枯渇のトラブルシューティング

untitled

Aventail EX-2500/1600/750 STv(Ver.8.9) Sep 2007 c 2007 SonicWALL,Inc. All rights reserved.

untitled

DocuWide 2051/2051MF 補足説明書

AC3DGmst.ps

今日のトピック 実験結果の共有 RPKI/Router 周りの基本的な動き 今後の課題と展望 2012/7/6 copyright (c) tomop 2

Actual ESS Adapterの使用について

意外と簡単!?

IP 2.2 (IP ) IP 2.3 DNS IP IP DNS DNS 3 (PC) PC PC PC Linux(ubuntu) PC TA 2

Systemwalker IT Service Management Systemwalker IT Service Management V11.0L10 IT Service Management - Centric Manager Windows

スライド 1

R80.10_FireWall_Config_Guide_Rev1

Express5800/R110a-1Hユーザーズガイド

RouteMagic Controller RMC-MP200 / MP Version

Oracle Application Server 10g(9

Oracle Application Server 10g( )インストール手順書

目 次 1 改 訂 履 歴 はじめに L2 ACL 基 本 設 定 L2 ACL の 作 成 L2 ACL のインタフェースまたは VLAN への 適 用 L2 ACL の 設 定 の 確 認 L3 AC

Express5800/320Fc-MR

DIRECTIONS

SRX300 Line of Services Gateways for the Branch

Express5800/320Fa-L/320Fa-LR

tcp/ip.key

Metasploit 2012.indb

ISE 2.1 および AnyConnect 4.3 ポスチャ USB チェックの設定

アライドテレシス ディストリビューション・スイッチ AT-x600シリーズで実現するMicrosoft® NAP

Juniper NetworksJunosSteel-Belted RadiusNetScreenScreenOS Juniper Networks, Inc. Juniper Networks Junos JunosE Juniper Networks, Inc. Juniper Networks

RouteMagic Controller( RMC ) 3.6 RMC RouteMagic RouteMagic Controller RouteMagic Controller MP1200 / MP200 Version 3.6 RouteMagic Controller Version 3

RX600 & RX200シリーズ アプリケーションノート RX用仮想EEPROM

SR-X324T1/316T1 サーバ収容スイッチ ご利用にあたって

橡CoreTechAS_HighAvailability.PDF

All Rights Reserved. Copyright(c)1997 Internet Initiative Japan Inc. 1

Elastic stack Jun Ohtani 1

US40cユーザーズガイド

リング型IPカメラ監視ソリューション(マルチキャスト編)

untitled

untitled

リング型IPカメラ監視ソリューション

QOS.dvi

VNSTProductDes3.0-1_jp.pdf

nakayama15icm01_l7filter.pptx

R76/Gaia ブリッジ構成設定ガイド

F コマンド

untitled

QoS.dvi

ArrayAPV/TMX 負荷分散機能の基本

RouteMagic Controller RMC-MP200 / MP Version

Introduction Purpose This training course describes the configuration and session features of the High-performance Embedded Workshop (HEW), a key tool


untitled

破損した CIMC ファームウェアの復旧

dvi

Transcription:

IDP (INTRUSION DETECTION AND PREVENTION)

SRX IDP Full IDP Stateful Inspection 8 Detection mechanisms including Stateful Signatures and Protocol Anomalies Reassemble, normalize, eliminate ambiguity Track sessions Packets Application Traffic 0000000000000000000000000000000000 0000000000000000000000000000000000 0000000000000000000000000000000 XOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXO XOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXOXO XOXOXOXOXOXOXOXOXOOXOXOXOXOX OXOXOXOXOXOXOXOXOXOXOXOXOXOX XOXOXOXOXOXOXOXOXOXOXOXOXOXO Application Traffic Deny Some Attacks Deny Traffic SRX IDP SRX 2 Copyright 2009 Juniper Networks, Inc. www.juniper.net

脆弱性や新たな脅威を研究する専任チーム プロトコルデコードのノウハウ 複数の研究機関やベンダーとのパートナーシップ リバース エンジニアリングの専門家 グローバルなハニーポット ネットワーク 業界トップクラスのレスポンスタイム シグネチャを毎日更新 グローバルに分散配置したチーム 緊急時は数時間以内または数分以内に更新 www.juniper.net/security 3 Copyright 2009 Juniper Networks, Inc. www.juniper.net

IDP

IDP IDP IDP 5 Copyright 2009 Juniper Networks, Inc. www.juniper.net

IDP ) lab@srx1> request system license add? Possible completions: <filename> Filename (URL, local, remote, or floppy) terminal Use login terminal lab@srx1> show system license License usage: Licenses Licenses Licenses Expiry Feature name used installed needed idp-sig 0 1 0 2010-12-28 09:00:00 JST 6 Copyright 2009 Juniper Networks, Inc. www.juniper.net

IDP ( DNS ) lab@srx1> request security idp security-package download check-server Successfully retrieved from(https://services.netscreen.com/cgi-bin/index.cgi). Version info:1687(detector=10.3.160100319, Templates=2) lab@srx1> request security idp security-package download 7 Copyright 2009 Juniper Networks, Inc. www.juniper.net

Status lab@srx1> request security idp security-package download status In progress: Downloading... lab@srx1> request security idp security-package download status In progress:signatureupdate_tmp.xml.gz 100 % 1174171 Bytes/ 1174171 Bytes lab@srx1> request security idp security-package download status Done;Successfully downloaded from(https://services.netscreen.com/cgibin/index.cgi). Version info:1687(fri May 21 12:48:07 2010, Detector=10.3.160100319) 8 Copyright 2009 Juniper Networks, Inc. www.juniper.net

lab@srx1> request security idp security-package install Status lab@srx1> request security idp security-package install status In progress:performing DB update for an xml (SignatureUpdate.xml) lab@srx1> request security idp security-package install status Done;Attack DB update : successful - [UpdateNumber=1687,ExportDate=Fri May 21 12:48:07 2010,Detector=10.3.160100319] Updating control-plane with new detector : successful Updating data-plane with new attack or detector : not performed due to no existing running policy found. 9 Copyright 2009 Juniper Networks, Inc. www.juniper.net

lab@srx1> show security idp security-package-version Attack database version:1687(fri May 21 12:48:07 2010) Detector version :10.3.160100319 Policy template version :N/A 10 Copyright 2009 Juniper Networks, Inc. www.juniper.net

IDP lab@srx1> request security idp security-package download policy-templates lab@srx1> request security idp security-package download status Done;Successfully downloaded from(https://services.netscreen.com/cgibin/index.cgi). Version info:2 11 Copyright 2009 Juniper Networks, Inc. www.juniper.net

lab@srx1> request security idp security-package install policy-templates lab@srx1> request security idp security-package install status Done;policy-templates has been successfully updated into internal repository (=>/var/db/scripts/commit/templates.xsl)! lab@srx1# set system scripts commit file templates.xsl 12 Copyright 2009 Juniper Networks, Inc. www.juniper.net

lab@srx1# run show security idp policy-templates-list Web_Server DMZ_Services DNS_Service File_Server Getting_Started IDP_Default Recommended 13 Copyright 2009 Juniper Networks, Inc. www.juniper.net

IDP IDP rule 1. rulebase-ips match from-zone to-zone source-address destination-address application lab@srx1# set security idp idp-policy idp-policy-1 rulebase-ips rule 1 match fromzone any to-zone any source-address any destination-address any application default attacks predefined-attack-groups [Critical Major] 14 Copyright 2009 Juniper Networks, Inc. www.juniper.net

IDP 2. no-action - ( ) ignore - drop-packet - drop-connection - close-client - RST close-server RST close-client-and-server RST mark-diffserv DSCP recommended Juniper lab@srx1# set security idp idp-policy Intranet rulebase-ips rule 1 then action drop-connection 15 Copyright 2009 Juniper Networks, Inc. www.juniper.net

IDP 3. notification lab@srx1# set security idp idp-policy Intranet rulebase-ips rule 1 then notification log-attacks 16 Copyright 2009 Juniper Networks, Inc. www.juniper.net

IDP 4. IP IP ip-notify ( ) ip-close ip-block lab@srx1# set security idp idp-policy Intranet rulebase-ips rule 1 then ipaction ip-close 17 Copyright 2009 Juniper Networks, Inc. www.juniper.net

IDP IDP lab@srx1# set security idp active-policy idp-policy-1 18 Copyright 2009 Juniper Networks, Inc. www.juniper.net

IDP lab@srx1# set security policies from-zone trust to-zone untrust policy trust-tountrust match source-address any destination-address any application any lab@srx1# set security policies from-zone trust to-zone untrust policy trust-tountrust then permit application-services idp 19 Copyright 2009 Juniper Networks, Inc. www.juniper.net

IDP CONFIGURATION lab@srx1# show security idp idp-policy idp-policy-1 { rulebase-ips { rule 1 { match { from-zone any; source-address any; to-zone any; destination-address any; application default; attacks { predefined-attack-groups [ Critical Major ]; } } then { action { drop-connection; } ip-action { ip-close; } notification { log-attacks; } } } } } 20 Copyright 2009 Juniper Networks, Inc. www.juniper.net

show security idp lab@srx1> show security idp? Possible completions: application-identification Show IDP application identification data application-statistics Show IDP application statistics attack Show IDP attack data counters Show IDP counters memory Show IDP data plane memory statistics policies Show the list of currently installed policies policy-templates-list Show available policy templates security-package-version Show the version of currently installed security-package status Show IDP status 21 Copyright 2009 Juniper Networks, Inc. www.juniper.net

lab@srx1> show security idp memory IDP data plane memory statistics: Total IDP data plane memory : 212 MB Used : 20 MB ( 20480 KB ) ( 9.43%) Available : 192 MB ( 196608 KB ) ( 90.57%) 22 Copyright 2009 Juniper Networks, Inc. www.juniper.net

lab@srx1# run show security idp status State of IDP: Disabled, Up since: 2010-09-17 17:23:19 UTC (00:40:42 ago) Packets/second: 0 Peak: 0 @ 2010-09-17 17:23:19 UTC KBits/second : 0 Peak: 0 @ 2010-09-17 17:23:19 UTC Latency (microseconds): [min: 0] [max: 0] [avg: 0] Packet Statistics: [ICMP: 0] [TCP: 0] [UDP: 0] [Other: 0] Flow Statistics: ICMP: [Current: 0] [Max: 0 @ 2010-09-17 17:23:19 UTC] TCP: [Current: 0] [Max: 0 @ 2010-09-17 17:23:19 UTC] UDP: [Current: 0] [Max: 0 @ 2010-09-17 17:23:19 UTC] Other: [Current: 0] [Max: 0 @ 2010-09-17 17:23:19 UTC] Session Statistics: [ICMP: 0] [TCP: 0] [UDP: 0] [Other: 0] Policy Name : idp-policy-1 23 Copyright 2009 Juniper Networks, Inc. www.juniper.net