How to create custom vulnerability signature for SIP packets?

Reply
L1 Bithead

How to create custom vulnerability signature for SIP packets?

Hi,

we are trying to create  custom vulnerability signature for triggering on the specific string in the udp packet payload with  destination port 5060. Unfortunately there is no context for SIP. We used "Pattern Match" and chose "unknown -req-udp-payload" as a context. We applied a Vulnerability protection profile to the security policy (a rule allowing everything) but for some reason this didn't work as we expected. I mean we didn't receive any alert in the Threat log.

Is it possible to use "unknown -req-udp-payload" context for such purpose or it is intended only for the "unknown-udp" applications? Any other idea for creating such signature?

Thanks.

Leonid

Highlighted
L7 Applicator

Re: How to create custom vulnerability signature for SIP packets?

You'll need to contact TAC and ask for them to open up SIP contexts in custom vulnerability signatures.  This is something that can be done through a content update.  The "unknown" contexts you refer to are only applicable to "unknown-tcp" and "unknown-udp" App-IDs. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!