Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

SSIM 4.6.1.24 and Symantec Endpoint Protection

Updated: 23 May 2010 | 5 comments
JackieSYK@Gmail.com's picture
0 0 Votes
Login to vote

SSIM Version: 4.6.1.24
SEP Version: 11

Symptom: Many "Trojan Connections" incidents appear everyday.

Most Target Resource:

1) C:/WINNT/system32/LSASS.EXE
2) C:/WINDOWS/system32/lsass.exe
3) C:/WINNT/system32/dns.exe
4) C:/WINDOWS/system32/dns.exe

Destination Port Range: 1024 to 65432

Most of incidents look like normal traffic, and just match the known port list so that the incident pop up

How can customize the orignal rule set to reduce it, or any other suggestion

Discussion Filed Under:

Comments

Intasunta N.'s picture
12
May
2009
0 Votes 0
Login to vote

You can not change default

You can not change default rule set. But you can copy as template then customize the rule as your need. And don't forget to disable the old one.

shaun_b's picture
13
May
2009
1 Vote +1
Login to vote

Aggregation

You can think about using aggregation on the SSIM collector, or configure SEP to aggregate these events as well. 

http://service1.symantec.com/support/ent-gate.nsf/...

hackajar's picture
22
Sep
2009
0 Votes 0
Login to vote

What is the benifit to having

What is the benifit to having this rule trigger on Internal -> Internal traffic?  Escpeically since firewalls always got directions mixed up?  can't the default rule add "Connection = Outbound" via Live Update to tune the rule to more accurate traffic?

shaun_b's picture
23
Sep
2009
0 Votes 0
Login to vote

What I do is edit that rule

What I do is edit that rule to reflect external traffic just like you mentioned. Also take a look at the trojan list of ports, and remove things that have been validated as false positives within your environment.

Laurent_c's picture
09
Oct
2009
0 Votes 0
Login to vote

Before any of this works, you

Before any of this works, you need to make sure you define your networks, if you only have the 3 default networks setup a lot of rules will trigger when they should not. Right afterinstalling SSIM, one of first task should be to set up all the subnets.

Laurent