Endpoint Protection

 View Only
  • 1.  I need advice in interpreting Network Threat log

    Posted Jun 02, 2012 06:19 PM

    I started having unexplained trouble with my curser movement with my laptop, so I activated Endpoint Network protection on the laptop to track outgoing traffic. I'm getting warnings every few minutes from Symantec. I've copied examples below. Some of the warnings are threat level 10, which go straight through. Some are threat level 3, which are blocked. I don't know why the threat level 10 traffic isn't blocked. I also can't trace where the source of this traffic is coming from. I did a whole system scan, and Symantec didn't pick up anything. When I tried to Back Trace, I get the message that these are an "Invalid IP for backtracing". How can I find where this traffic is coming from, and if it is a threat, to remove it from my computer?

    6/2/2012 5:54:23 PM   Blocked    3    Outgoing     IPv6 [type=0x86DD] 0.0.0.0 33-33-00-00-00-0C 0 0.0.0.0 E4-D5-3D-6A-4B-94 0  GUI%GUICONFIG#SRULE@ADVRULECONFIG#Normal_102 
     

    6/2/2012 5:54:23 PM    Allowed    10    Outgoing    IP 224.0.0.22 01-00-5E-00-00-16 NA 172.16.0.4 E4-D5-3D-6A-4B-94 NA  Allow IGMP to Pass Through 


    6/2/2012 5:54:23 PM    Blocked    3    Outgoing     IPv6 [type=0x86DD]    0.0.0.0 33-33-00-00-00-0C 0 0.0.0.0 E4-D5-3D-6A-4B-94 0  GUI%GUICONFIG#SRULE@ADVRULECONFIG#Normal_102

     
    6/2/2012 5:47:36 PM    Allowed    10    Outgoing     UDP 172.16.0.255    FF-FF-FF-FF-FF-FF 138 172.16.0.4 E4-D5-3D-6A-4B-94 138 C:\windows\system32\ntoskrnl.exe GUI%GUICONFIG#SRULE@NBENABLEYOU#ALLOW-UDP 
     



  • 2.  RE: I need advice in interpreting Network Threat log

    Posted Jun 03, 2012 03:39 PM

    Hi,

    the threat level is not technically relevant at all, you may alter it at your convenience and give it the meaning you want. The Network Threat logs should also tell you the source of the traffic.

    The SEP agent also has Network Monitor, a useful tool to monitor network activities. You may also use Microsoft's tools like netstat, process monitor, process explorer, etc. to know everything you want about running processes.



  • 3.  RE: I need advice in interpreting Network Threat log

    Trusted Advisor
    Posted Jun 04, 2012 04:25 AM

    Hello,

    What version of SEPM / SEP are you running?

    Check this Article:

    Symantec Endpoint Protection - Network Threat Protection traffic log shows "GUI%GUICONFIG#SRULE@ADVRULECONFIG#Normal" instead of the rule function or the rule name

    http://www.symantec.com/docs/TECH95646

    Hope that helps!!