How to create custom vulnerability signature for SIP packets?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How to create custom vulnerability signature for SIP packets?

L1 Bithead

Hi,

we are trying to create  custom vulnerability signature for triggering on the specific string in the udp packet payload with  destination port 5060. Unfortunately there is no context for SIP. We used "Pattern Match" and chose "unknown -req-udp-payload" as a context. We applied a Vulnerability protection profile to the security policy (a rule allowing everything) but for some reason this didn't work as we expected. I mean we didn't receive any alert in the Threat log.

Is it possible to use "unknown -req-udp-payload" context for such purpose or it is intended only for the "unknown-udp" applications? Any other idea for creating such signature?

Thanks.

Leonid

5 REPLIES 5

L5 Sessionator

Following Tech note explains usage a each context for creating a Custom Threat Signature

Creating Custom Threat Signatures

L5 Sessionator

Good Morning,

We have a couple of avenues that you can check for assistance with custom signatures. You can post on the DevCenter (found on our support portal under communities - https://live.paloaltonetworks.com/community/devcenter) or you can request that an official signature be made through Applipedia (http://researchcenter.paloaltonetworks.com/submit-an-application/)

Best regards,

Karthik

L7 Applicator

You'll need to contact TAC and ask for them to open up SIP contexts in custom vulnerability signatures.  The SIP contexts are not open to the public today, but could be made available through a content update.  The "unknown" contexts you refer to are only applicable to "unknown-tcp" and "unknown-udp" App-IDs.  Since your traffic is identified as SIP, your existing custom signature will not match. 

By the way, how come that for example the SIP context is closed by default?

Seems like an neverending stream of feature requests to the SE's 😃

These aren't the same as Feature Requests that have to be rolled-up to your SE and then coded into the next version of PAN-OS.  The contexts already exist and just need to be a.) QA'd for public consumption, and then b.) opened to the public via the weekly content update.  I hear you, though.  I'd love to see all of the contexts opened up.  Then again, in my day-to-day I've been able to create all of the custom App-ID and Vulnerability signatures with the contexts that have already been published.    

  • 2699 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!