Endpoint Protection Security Update 103
Updated: 22 May 2010 | 4 comments
I noticed that the below IPS detections have been updated with today's IPS security update.
Yahoo! IM File Transfer Low
Yahoo! IM Login Low
Yahoo! IM Activity Low
Yahoo! Conference Login Low
Yahoo! Ping
I verified that my SEP client had the update in question. So I thought, cool, I can test how the Symantec IPS works in our environment. I downloaded Yahoo instant messenger on a SEP MR4 managed computer and logged into Yahoo and sent a couple of IM's to see if I would get notified of the activity via SEPM. I got nothing. Is there some special trick to triggering this alert?
discussion Filed Under:
Comments
About notifications
Hi,
I think you have to set a proper notification up. SEP is so reach of events that by default most of them are disabled or sent when a threshold of severity or frequency is reached to avoid a flood of notifications on the admin mail box.
Try the Report and Monitor sections to filter the clients' logs and find the IPS detections.
The SEP Reporting is a big topic, read the product documentation to get more details.
Regards,
Giuseppe
IPS for YAHOO
As per my understanding:
For all the mentioned signatures below:
Details on the IPS signatures released as we can see it in the links:
http://www.symantec.com/business/security_response...
http://www.symantec.com/business/security_response...
http://www.symantec.com/business/security_response...
http://www.symantec.com/business/security_response...
http://www.symantec.com/business/security_response/attacksignatures/detail.jsp?asid=20571
The Response Part in ALL the documents mention that:
RESPONSE:
While some organizations permit the legitimate use of instant messengers on networks, these programs should be monitored for potential malicious software.
WHICH LOOKS LIKE:
These programs would only be monitored for potential malicious software detection and the normal functionality of YAHOO would not be affected at any point in time
Kedar Mohile http://kedarmohile.blogspot.com
You need to go into
You need to go into Policy->IPS policy->exceptions->find those sigs then change the default behavior from "allow, don't log" -> "Block, log"
re: You need to go into
rwessen's comment is what worked. I didn't realize that there were IPS signatures that were not active. I changed all of the ones set from don't block, don't log, to allow, log to see what else might be detected.
this might make for a good forum post down the road, I had no idea these signatures were "on ice."
Would you like to reply?
Login or Register to post your comment.