ISS Proventia Inline Appliance Policy
[ issPolicy v1.01 | http://packet.sequenced.org/projects/isspolicy ]



POLICY INFORMATION

   Policy File: policies/AttackBlocker_inline.policy
   Policy Name: Attack Blocker
   Policy Version: 8.0.2004.286
   Sensor Type: Proventia Inline Appliance (v8.0)


SIGNATURES POLICY

Response Summary Legend: DISPLAY | LOGDB | EMAIL | SNMP | RSKILL | OPSEC | LOGEVIDENCE | DROP | DYNAMICBLOCK

Signature NameSignature DescriptionSignature StatusSignature PriorityResponse SummaryLogDropDynamicBlock
BoinkBoink DoSEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
BonkBonk DoSEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
DeepThroat_ResponseDeepThroat BackdoorEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
ICQ_PAM_Parser_OverflowICQ Overflow AttemptEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
ICQ_Witty_WormICQ Witty WormEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
IP_Invalid_OptionInvalid IP OptionEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
IP_Tunnel_Bad_VersionIP tunnel bad versionEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
Mstream_Zombie_ResponseMstream agent activityEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
NesteaNestea attackEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
NewTearNewTear attackEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
Quake_Backdoor_RequestQuake backdoorEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
SQL_SSRP_Slammer_WormMS Sql Server 2000 Resolution Service Slammer WormEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
SQL_SSRP_StackBoMS Sql Server 2000 Resolution Service stack overflowEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
Slapper_WormDetect Slapper P2P activityEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
Snort_Stream4_HeapBoSnort stream4 heap overflowEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
Symantec_NBNS_BoSymantc Firewall NetBIOS Name Service (NBNS) Response Buffer OverflowEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
SynDropSynDrop attackEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
TCP_Frag_RFProwlRFProwl exploitEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
TFTP_MSBlaster_AttemptTFTP msblaster.exe transfer attemptEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
TFTP_MSBlaster_WormTFTP msblaster.exe file transferEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
TFTP_Nachi_WormTFTP dllhost.exe and svchost.exe file transferEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
TearDropTeardrop attackEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
Trin00_Daemon_ResponseTrin00 Distributed Denial of Service DaemonEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
Unexplained_Backdoor_ResponseUnexplained BackdoorEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
Win_IP_Src_RouteWindows IP Source RoutingEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled


USER-DEFINED IP FILTERS

Filter NameFilter DescriptionFilter StatusProtocolSource Address/Mask [Asset]Source PortDestination Address/Mask [Asset]Destination Port
FR-PAR-NESSUSInternet Scanner Vulnerability Assessment host (Paris, France)Enabledip1.2.3.4/32ANYANYANY
UK-LON-NESSUSInternet Scanner Vulnerability Assessment host (London, United Kingdom)Enabledip4.3.2.1/32ANYANYANY
GLOBAL-MCAST-VRRPGlobal multicast VRRP trafficDisabledipANYANY224.0.0.18/24ANY



USER-DEFINED EVENT FILTERS

Filter NameFilter DescriptionFilter StatusFiltered EventSource AddressSource PortDestination AddressDestination Port
AU-SYD-SNMP-001SNMP_Set Filter for Network Management Station (Sydney, Australia)EnabledSNMP_Set2.2.2.2ANY2.2.0.0-2.2.255.255161
MY-KUL-HTTP-001Microsoft ASP.NET vulnerability against Apache web server (Kuala Lumpur, Malaysia)DisabledHTTP_ASP_Security_BypassANYANY3.3.3.380


[ Generated using: issPolicy v1.01 - http://packet.sequenced.org/projects/isspolicy ] [ Author: Kristof Philipsen / kphilipsen@gmail.com ]