<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question on Anti-Spyware DNS signatures in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-anti-spyware-dns-signatures/m-p/42659#M31321</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as far as I understand Anti-Spyware profiles, the DNS options will find DNS lookups to known malware sites. How exactly does this work? Will the actual DNS lookup be blocked or will the client's access to the site be blocked?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quote from the documentation:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;Additionally, hosts that perform DNS queries for malware domains will appear in the botnet report. DNS signatures are downloaded as part of the antivirus updates.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;What if hosts use an internal DNS server? That would result in only the DNS server showing up in the botnet report?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 01 Jun 2013 13:27:08 GMT</pubDate>
    <dc:creator>cryptochrome</dc:creator>
    <dc:date>2013-06-01T13:27:08Z</dc:date>
    <item>
      <title>Question on Anti-Spyware DNS signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-anti-spyware-dns-signatures/m-p/42659#M31321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as far as I understand Anti-Spyware profiles, the DNS options will find DNS lookups to known malware sites. How exactly does this work? Will the actual DNS lookup be blocked or will the client's access to the site be blocked?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quote from the documentation:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;Additionally, hosts that perform DNS queries for malware domains will appear in the botnet report. DNS signatures are downloaded as part of the antivirus updates.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;What if hosts use an internal DNS server? That would result in only the DNS server showing up in the botnet report?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'Microsoft Sans Serif';"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Jun 2013 13:27:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-anti-spyware-dns-signatures/m-p/42659#M31321</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-06-01T13:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Anti-Spyware DNS signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-anti-spyware-dns-signatures/m-p/42660#M31322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...The default action is to alert(log) these DNS lookups.&amp;nbsp; You can configure the action for the DNS signature in the anti-spyware profile as seen:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/6729_pastedImage_0.png" style="width: 372px; height: 207px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only the DNS query matching the DNS signature will be block. Other DNS query not matching will be allow through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If all external DNS queries are performed by an internal DNS server, then yes the botnet report would show the source as the internal DNS server.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Jun 2013 15:41:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-anti-spyware-dns-signatures/m-p/42660#M31322</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2013-06-02T15:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: Question on Anti-Spyware DNS signatures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-on-anti-spyware-dns-signatures/m-p/42661#M31323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks &lt;A __default_attr="2357" __jive_macro_name="user" class="jive_macro jive_macro_user" data-objecttype="3" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; - much appreciated. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Jun 2013 15:51:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-on-anti-spyware-dns-signatures/m-p/42661#M31323</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2013-06-02T15:51:23Z</dc:date>
    </item>
  </channel>
</rss>

