<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom App for SIP in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-for-sip/m-p/174221#M200</link>
    <description>&lt;P&gt;Logged as SIP which is what is supposed to be since they are an VoIP provider. I have no pcap files currently.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Aug 2017 18:22:54 GMT</pubDate>
    <dc:creator>markibr</dc:creator>
    <dc:date>2017-08-31T18:22:54Z</dc:date>
    <item>
      <title>Custom App for SIP</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-for-sip/m-p/173910#M195</link>
      <description>&lt;P&gt;As a SIP provider, looking for&amp;nbsp;to create&lt;SPAN&gt;&amp;nbsp;a custom signature that matches a SUBSCRIBE message from the packet payload w/ 10 or 11 digits.&amp;nbsp;We first tried this w/ Data Patterns under the Custom Objects but that didn't solve/address our issues.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We then created a custom app (SIP-SUBSCRIBE) to match the sip application already available in the DB, and then created a new signature called 'Subscribe' with a 'Session' Scope type. Furthermore, we selected the "Ordered Condition Match" in order to actually be able to match a regex string against the packet. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The regex in question was written as follows: .*(SUBSCRIBE sip:[0-9]\{10-11}@)&lt;FONT color="#000000"&gt; and is to match any sip packet w/ a Subscribe message containing a string of 10 or 11 digits. (&lt;I&gt;At least, that was our intention&lt;/I&gt;)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#000000"&gt;We then created a security rule where we matched the custom application called SIP_SUBSCRIBE and set it to Allow at first so we could see that it was actually matching what we were looking for but unfortunately didn't see any matches. (&lt;I&gt;Even though the attack was still ongoing&lt;/I&gt;)&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 17:36:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-for-sip/m-p/173910#M195</guid>
      <dc:creator>markibr</dc:creator>
      <dc:date>2017-08-30T17:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App for SIP</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-for-sip/m-p/174106#M196</link>
      <description>&lt;P&gt;Hi Markibr,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How was the attack logged, as which application? Do you have any pcaps from that, a session or two? Did you already open a case with support?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 12:18:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-for-sip/m-p/174106#M196</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2017-08-31T12:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Custom App for SIP</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-for-sip/m-p/174221#M200</link>
      <description>&lt;P&gt;Logged as SIP which is what is supposed to be since they are an VoIP provider. I have no pcap files currently.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 18:22:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-app-for-sip/m-p/174221#M200</guid>
      <dc:creator>markibr</dc:creator>
      <dc:date>2017-08-31T18:22:54Z</dc:date>
    </item>
  </channel>
</rss>

