Endpoint Protection

 View Only
Expand all | Collapse all

SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

  • 1.  SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 08, 2012 11:21 PM

    Hi All,

    As per topic, how does Symantec rate exploit/vulnerability before adding it to SEP IPS signatures?

     

    Does it add "in the wild" exploit as well? How about exploit to Apache and such?

     

    Let say certain exploit is detected by different IPS (hardware IPS) but not by SEP IPS, how does we escalate it?

     

     

     

    regards



  • 2.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 08, 2012 11:26 PM

    It is based on th signature...The signatures based on the SYmantec Site



  • 3.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Broadcom Employee
    Posted Mar 08, 2012 11:48 PM

    how does Symantec rate exploit/vulnerability before adding it to SEP IPS signatures?

    Security response team looks into this before adding into IPS signature. THe ratings mostly have CVE.

     

    Does it add "in the wild" exploit as well? How about exploit to Apache and such?

    check these list of signatures available

    http://www.symantec.com/security_response/attacksignatures/

     

    Let say certain exploit is detected by different IPS (hardware IPS) but not by SEP IPS, how does we escalate it? 

    you can talk to support  and request for addition of signature in SEP IPS.



  • 4.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 08, 2012 11:51 PM


  • 5.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 09, 2012 01:51 AM

    Can anbody help check whether this CVE is covered by SEP IPS?

    cve:2011-3192

     

    If it's not the list just request for additional signature?

    How does it works? Just forward the CVE number?



  • 6.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Broadcom Employee
    Posted Mar 09, 2012 02:24 AM

    yep, covered

    check this link

    Attack: Apache and IIS Range DoS

    http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=24454

     

    you should be working with support on the query and the vulnerability that has been seen,



  • 7.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 09, 2012 04:15 AM

    First of all thank you Pete.

    Let me be honest, the support kinda "blur" this time.... he should point out that this exploit is covered by SEP IPS at the very beginning..

     

    I'll wait until he reach that point....

     

    How can i search on Symantec side if any other exploit is covered by SEP IPS?

    Do i need to look for it manually per application name? (in this case affected application is Apache)

     



  • 8.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Broadcom Employee
    Posted Mar 09, 2012 05:01 AM

    see if this helps

    visit this page

    http://www.symantec.com/security_response/attacksignatures and there is search on the right hand top corner enter the CVE number and do search and try to figure out the IPS signature URL

    or click on each signature.



  • 9.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 09, 2012 08:24 AM
    We write our own SEP custom IPS signatures if none exists with Symantec. We use either Snort rules and re-write for SEP or we actually use packet sniffing traces to build a signature.


  • 10.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 11, 2012 10:34 PM

    @pete

    thanks again, the search using CVE number is working fine

    what are the rate of exploit signature added to SEP IPS vs daily exploit found?

     

    @thatdude,

    is snort rule 100% compatible with SEP custom IPS? or do we need to alter it?

    do you have any other guide than provided by Symantec, it does not really in-depth...

     



  • 11.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Broadcom Employee
    Posted Mar 11, 2012 11:35 PM

    IPS signatures are usually releases 2 times a week as per the pattern.

    SNORT code are compatible.



  • 12.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 11, 2012 11:48 PM

    @pete

    1) by saying compatible means no changes are needed? we can just copy n paste it to the rule column?

    2) do you have any in-depth guide for SEP custom IPS?

     

    also how long is 2 weeks for IPS signature update standard? how does it fare with other brand/rival?

    (fully understand that SEP is not dedicated IPS...but let say there's a 0day... 2 weeks is quite long)



  • 13.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 11, 2012 11:53 PM
    You have to edit the SNORT rule before using it in SEP. I've got a request in with the product team to create a SNORT to SEP IPS conversion utility to makes things easier for admins.


  • 14.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Broadcom Employee
    Posted Mar 11, 2012 11:56 PM

    1) by saying compatible means no changes are needed? we can just copy n paste it to the rule column?

    you need to edit it.

    2) do you have any in-depth guide for SEP custom IPS?

    click on the help and please check the forums ( articles)



  • 15.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 12, 2012 02:44 AM

    Ok i got the snort rule here for this particular CVE, can anyone help to convert to SEP Custom IPS?

     

    alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"DOS Apache Killer denial of service tool exploit attempt"; flow:to_server,established; content:"Range"; nocase; http_header; content:"bytes"; within:10; nocase; http_header; pcre:"/Range\s*\x3A\s*bytes=([\d\x2D]+\x2C){50}/Hsmi"; reference:bugtraq,49303; reference:cve,2011-3192; reference:url,archives.neohapsis.com/archives/fulldisclosure/2011-08/0203.html; reference:url,osvdb.org/show/osvdb/74721; classtype:attempted-dos; sid:19825; rev:6;)

     

     

    Many thanks!!



  • 16.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 12, 2012 10:29 PM

    Anyone?

    It would be helpful as an example of snort conversion to SEP custom IPS..



  • 17.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Broadcom Employee
    Posted Mar 13, 2012 12:24 AM


  • 18.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 13, 2012 05:50 AM

    I'm having headache to convert this snort to SEP custom IPS...

    lack of documentation really making it hard

     

     

    Any future plan to release more info about this SEP custom IPS? I've re-checked SEP manual... so far did not find any example



  • 19.  RE: SEP 11: How does Symantec rate exploit/vulnerability before adding it to SEP IPS?

    Posted Mar 14, 2012 09:52 PM

    Anybody got a good paper about packet capture/IPS analysis?

    I've found a few but still need suggestion from fellow Symantec user...