- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
08-24-2011 11:43 PM
Hi,
I was reading the 2011-2012 buyers giude. There is a statement that describes Base64 encoded HTTP messages , used in command and control traffic for malware.
The bot sets the User-Agent header value to “inter easy” and also receives a scrambledBase64 encoded command which means “sleep”: <!-- 2upczxAX.3
Most network security controls would pass this bot’s traffic withno complaints, as it appears to resemble common Web applicationtraffic. If a firewall was capable of analyzing all HTTP andHTTPS traffic and determine that the traffic was anomalous insome way, either based on behavior patterns of browsing, or theunusual request and response strings or patterns, then this couldpotentially be blocked. However, even most intrusion detectionand prevention devices today would rely on a standard signaturebasedmethod to detect this, and most likely wouldn’t.
How does Palo Alto firewalls deal with such traffic ? I guess it would have to rely on signatures itself right ? , But the Botnet detection logic would let you see if these patterns would be going to known malware links? . I am trying to get past markeing and understand how it really works.
One more question , If I set up my own websever at home and connected to that on IP address, Will Palo flag that as unusual trafiic ? and where can I see that? and how do I reliably block that ?
Thanks ,
Sunil
08-29-2011 01:05 PM
@sunilsadanandan:
In the first scenario you describe, we would most likely write a signature for the user-agent string.
In the second scenario we could allow, alert or block the traffic to your web server at home based upon URL filtering. Since your server at your house would probably not be categorized by any URL filtering service it would probably match the "unknown" category.
-Benjamin
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!