Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Endpoint Protection Security Update 103

Updated: 22 May 2010 | 4 comments
tekkid's picture
0 0 Votes
Login to vote

I noticed that the below IPS detections have been updated with today's IPS security update. 
Yahoo! IM File Transfer Low
Yahoo! IM Login Low
Yahoo! IM Activity Low
Yahoo! Conference Login Low
Yahoo! Ping

I verified that my SEP client had the update in question.  So I thought, cool, I can test how the Symantec IPS works in our environment.   I downloaded Yahoo instant messenger on a SEP MR4 managed computer and logged into Yahoo and sent a couple of IM's to see if I would get notified of the activity via SEPM.  I got nothing.   Is there some special trick to triggering this alert?

Comments

Beppe's picture
13
May
2009
0 Votes 0
Login to vote

About notifications

Hi,

I think you have to set a proper notification up. SEP is so reach of events that by default most of them are disabled or sent when a threshold of severity or frequency is reached to avoid a flood of notifications on the admin mail box.
Try the Report and Monitor sections to filter the clients' logs and find the IPS detections.
The SEP Reporting is a big topic, read the product documentation to get more details.

Regards,

Giuseppe

Kedar Mohile's picture
13
May
2009
1 Vote +1
Login to vote

IPS for YAHOO

As per my understanding:

For all the mentioned signatures below:

  1. Yahoo! IM File Transfer Low
  2. Yahoo! IM Login Low
  3. Yahoo! IM Activity Low
  4. Yahoo! Conference Login Low
  5. Yahoo! Ping

Details on the IPS signatures released as we can see it in the links:

http://www.symantec.com/business/security_response...
http://www.symantec.com/business/security_response...
http://www.symantec.com/business/security_response...
http://www.symantec.com/business/security_response...
http://www.symantec.com/business/security_response/attacksignatures/detail.jsp?asid=20571

The Response Part in ALL the documents mention that:

RESPONSE:
While some organizations permit the legitimate use of instant messengers on networks, these programs should be monitored for potential malicious software.

WHICH LOOKS LIKE:
These programs would only be monitored for potential malicious software detection and the normal functionality of YAHOO would not be affected at any point in time

rwessen's picture
13
May
2009
1 Vote +1
Login to vote

You need to go into

You need to go into Policy->IPS policy->exceptions->find those sigs then change the default behavior from "allow, don't log" -> "Block, log"

tekkid's picture
13
May
2009
0 Votes 0
Login to vote

re: You need to go into

rwessen's comment is what worked.  I didn't realize that there were IPS signatures that were not active.   I changed all of the ones set from don't block, don't  log, to allow, log to see what else might be detected.   

this might make for a good forum post down the road, I had no idea these signatures were "on ice."