<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can the PAN device block HTTP Dos Attacks? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5567#M4071</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi hjlee.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can make a custom signature easily using as below info&lt;/P&gt;&lt;P&gt;&lt;IMG alt="스크린샷 2013-06-27 11.24.41 AM.png" class="jive-image-thumbnail jive-image" height="153" src="https://live.paloaltonetworks.com/legacyfs/online/7130_스크린샷 2013-06-27 11.24.41 AM.png" style="height: 153px; width: 609.2920353982302px;" width="609" /&gt;&lt;/P&gt;&lt;P&gt;But It's not important thing in real world because 7.7 DDOS attack of Korea was not related certainly above and HTTP Get flooding and UDP flooding that made it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Roh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Jun 2013 02:28:44 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-06-27T02:28:44Z</dc:date>
    <item>
      <title>Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5557#M4061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;I'm going to do some service availability test in the near future. We can't get any information of the attack pattern. The only information we know is that the tester will conduct these attack.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HTTP CC(cache-control) attack&lt;/LI&gt;&lt;LI&gt;Slowloris attack&lt;/LI&gt;&lt;LI&gt;Http post attack&lt;/LI&gt;&lt;LI&gt;Http Hash dos attack&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm afraid that those attack patterns seem to be normal for the PAN device (It's like brute force attack, working base on the threshold value)&lt;/P&gt;&lt;P&gt;I've heard that the best way to block these kinds of attacks is the setting server's timeout value or&amp;nbsp; threshold value.&lt;/P&gt;&lt;P&gt;But I have to find out some way to do this job with PAN.&lt;/P&gt;&lt;P&gt;Can we block those attack with IPS Dos Signature or Custom Signature?&amp;nbsp; If we can, does anyone know how set-up to the custom signature for those attacks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 05:36:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5557#M4061</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-06-19T05:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5558#M4062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;you can found explanation for DOS protection by paloalto with this doc &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-5078"&gt;https://live.paloaltonetworks.com/docs/DOC-5078&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but there is no information in this doc about HTTP DDOS.&lt;/P&gt;&lt;P&gt;I'm interresting in hhtp ddos too &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 06:02:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5558#M4062</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-06-19T06:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5559#M4063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;http ddos could be limited by rate limiting&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 06:05:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5559#M4063</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-06-19T06:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5560#M4064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ref : Resources Protection Page : 38 and &lt;/P&gt;&lt;P&gt;Appendix &lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; Slow HTTP Test Output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3094" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 06:29:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5560#M4064</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-06-19T06:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5561#M4065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think these attacks can exhaust server resource with normal Http transaction, and before the the server reaches its max concurrent connection limits, its resource worn out ..&lt;/P&gt;&lt;P&gt;And PA's Dos Protection uses Layer 3~4 information, &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;those attacks are based on Layer 7 information (Http get, post value etc...). In my opinion I should be able to set up Http get method threshold.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 06:59:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5561#M4065</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-06-19T06:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5562#M4066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You right about get flood,&amp;nbsp; but when a get request is sent you sent a tcp request and it 's why if you implement rate limiting you minimize the impact of this kind of attack&lt;/P&gt;&lt;P&gt;see &lt;A __default_attr="3439" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; how to implement QOS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 07:14:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5562#M4066</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-06-19T07:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5563#M4067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've found one IPS signatures which can block HTTP Slowloris attack.. :smileygrin:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE style="border: 1px solid #aaaaaa; color: #252525; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;TBODY&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Attack Name&lt;/TD&gt;&lt;TD class="detail-field" style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;HTTP: Apache Denial Of Service Attempt&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Description&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;This event indicates that someone want to exhaust the apache resources, as described by slowloris.&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Threat ID&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;40018&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;References&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;&lt;A href="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/40018" style="color: #505abc; text-decoration: underline;" target="_blank"&gt;https://threatvault.paloaltonetworks.com/Home/ThreatDetail/40018&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder" style="background-color: #d6e1e7;"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Severity&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;high&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="spaceunder"&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;Category&lt;/TD&gt;&lt;TD style="padding-top: 5px; padding-bottom: 5px; border-left-width: 1px; border-left-style: solid; border-left-color: #aaaaaa; border-right-width: 1px; border-right-style: solid; border-right-color: #aaaaaa;"&gt;brute-force&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 07:34:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5563#M4067</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-06-19T07:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5564#M4068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;good to know!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 07:49:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5564#M4068</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-06-19T07:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5565#M4069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think it's not exact for your case. HTTP: Apache DOS signature that triggered only 40 times in 60 second and only Apache related case. In my case I created a Custom Signature for HTTP post, CC that blocked in security rule while having BMT.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 05:44:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5565#M4069</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-21T05:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5566#M4070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="text-align: left; color: #575757; text-indent: 0px;"&gt;Dear My Lovely Roh..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Can you send me the custom signature information that you used for the BMT? :smileygrin:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks ahead..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 07:07:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5566#M4070</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-06-21T07:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5567#M4071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi hjlee.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can make a custom signature easily using as below info&lt;/P&gt;&lt;P&gt;&lt;IMG alt="스크린샷 2013-06-27 11.24.41 AM.png" class="jive-image-thumbnail jive-image" height="153" src="https://live.paloaltonetworks.com/legacyfs/online/7130_스크린샷 2013-06-27 11.24.41 AM.png" style="height: 153px; width: 609.2920353982302px;" width="609" /&gt;&lt;/P&gt;&lt;P&gt;But It's not important thing in real world because 7.7 DDOS attack of Korea was not related certainly above and HTTP Get flooding and UDP flooding that made it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Roh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 02:28:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5567#M4071</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-27T02:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5568#M4072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Roh, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I love You. :smileygrin:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 00:21:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5568#M4072</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-06-28T00:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5569#M4073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI, if you want the threat signature to trigger by a threshold value (i.e 30 hits in 10 sec), you can use the signature type=combination and define its time attribute.&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/7144_pastedImage_0.png" style="width: 596px; height: 199px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 14:07:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5569#M4073</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2013-06-28T14:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5570#M4074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CC Attack means Challenge Collapsar Response attack. In south Korea we call this 'Cache-control attack' .&lt;/P&gt;&lt;P&gt; To make combination signature we need basic signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my custom signature 41023 which block cache control message based on threshold value.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="cc2.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7178_cc2.png" width="450" /&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far I couldn't find any signature for Challenge Collapsar.&lt;/P&gt;&lt;P&gt;So I made custom signature for this attack.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ccc1.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7179_ccc1.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used my custom signature 41111 to make custom signature 41023 (combination signature working on threshold value).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you might know, the problem is signature 41111 work before 41023..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you guys have any solutions??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 02:52:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/5570#M4074</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-07-04T02:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can the PAN device block HTTP Dos Attacks?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/100921#M44321</link>
      <description>&lt;P&gt;This is an old issue but we still don't have signature for CC right now. Actually you shoud set the action of 41111 to allow, then 41023 can be triggered when threshold been reached.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 16:26:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-the-pan-device-block-http-dos-attacks/m-p/100921#M44321</guid>
      <dc:creator>StevenYin</dc:creator>
      <dc:date>2016-07-29T16:26:04Z</dc:date>
    </item>
  </channel>
</rss>

