Course Hero Logo

Week 5 Domain 4 Securing Traffic.pdf - Week 5: Domain 4...

Course Hero uses AI to attempt to automatically extract content from documents to surface to you and others so you can study better, e.g., in search results, to enrich docs, and more. This preview shows page 1 - 3 out of 8 pages.

Week 5: Domain 4 Securing Trafficp.133-163AntivirusAvs protect against viruses, worms, and trojans w/ spyware downloadsPalo Alto uses stream-based malware prevention. Engineinspects traffic the moment the firstpacket is received to provide protection forclient’sw/o significantly impacting performance ofthe firewall.Default profile inspects listed protocol decoders for viruses and generate alerts forSMTP, IMAP, and PoP3 protocols while blocking FTP, HTTP, and SMB protocols.Wildfire: provides signatures for persistent Threats that are evasive andhaven’tbeendiscovered by other Avs.Once discovered integrates them into normal AV signatures.oAdmin can download these signatures: sub-hourly.Anti-SpywareBlock SW on compromised hosts from communicating to C2 servers.Vulnerability ProtectionStop attempts to exploit system flaws/gain unauth access to systems.Anti-SW sec profiles identify infected hosts when traffic leaves netVulnerability Protection Sec profiles protect against threats entering net.oBuffer overflows, illegal code exe, etc.URL FilteringProfile determining web access/credential-submission permissions for URL cats.Default set to allow.Default set to no loggingDefault allows access to all URL cats except threat prone categories:oAbused-drugs, adult, gambling, hacking, malware phishing, questionable,weapons.User Cred Submission: allow or disallow users to submit valid corporate creds to URLcategories.oprevents credential phishing.
Wildfire AnalysisTurns PA Nets into a distributed sensor and enforcement point to stop zero-daymalware and exploits before they spread.oThreats detonates, intel gathered, prevention auto orchestrated across NG secproducts as soon as signatures generated.Multitechnique approach, combines dynamic/static analysis, machinelearning, and groundbreaking bare metal analysis.AntivirusagainDecoder actions:oDefault, usually an alert or reset both.oAllow……oAlert: Generates a alert saved in the threat log….shocker.oDrop……oReset Client: TCP resets client-side connectionUDP: drops itoReset Server: TCP resets server-side connection.UDP: DropsoReset Both: TCP resets connection on client and server.UDP: You will never guess…..Can make customized profiles to min av inspection on trusted security zones.oCan also max inspections for traffic on untrusted zones.Anti-SWDefault profiles: Default and StrictoStrict overrides default action of critical, high, medium severity threats to theblock action, regardless of defined action in signature file.After threat event is detected, you can configure the following actions for Anti-SpywareProfileoDefault:Default action of alert or reset-both.

Upload your study docs or become a

Course Hero member to access this document

Upload your study docs or become a

Course Hero member to access this document

End of preview. Want to read all 8 pages?

Upload your study docs or become a

Course Hero member to access this document

Term
Fall
Professor
Alfredo Perez
Tags
Domain Name System

Newly uploaded documents

Show More

  • Left Quote Icon

    Student Picture

  • Left Quote Icon

    Student Picture

  • Left Quote Icon

    Student Picture