How to create custom vulnerability signature for SIP packets?

Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to create custom vulnerability signature for SIP packets?

L1 Bithead


we are trying to create  custom vulnerability signature for triggering on the specific string in the udp packet payload with  destination port 5060. Unfortunately there is no context for SIP. We used "Pattern Match" and chose "unknown -req-udp-payload" as a context. We applied a Vulnerability protection profile to the security policy (a rule allowing everything) but for some reason this didn't work as we expected. I mean we didn't receive any alert in the Threat log.

Is it possible to use "unknown -req-udp-payload" context for such purpose or it is intended only for the "unknown-udp" applications? Any other idea for creating such signature?




L7 Applicator

You'll need to contact TAC and ask for them to open up SIP contexts in custom vulnerability signatures.  This is something that can be done through a content update.  The "unknown" contexts you refer to are only applicable to "unknown-tcp" and "unknown-udp" App-IDs. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!