Endpoint Protection

 View Only
  • 1.  How to: Intrusion Prevention

    Posted Nov 25, 2011 12:13 AM

    How you can test and proof that IP is working in SEP client?

    for example: to test AV, try with EICAR



  • 2.  RE: How to: Intrusion Prevention

    Broadcom Employee
    Posted Nov 25, 2011 12:25 AM

    Though this link is for custom IPS signature, you may need try checking this

    http://www.symantec.com/business/support/index?page=content&id=HOWTO55177



  • 3.  RE: How to: Intrusion Prevention

    Broadcom Employee
    Posted Nov 25, 2011 12:30 AM

    even any network tool like NMAP will be identified by IPS.



  • 4.  RE: How to: Intrusion Prevention

    Posted Nov 25, 2011 02:52 AM

     

    Step

    Action

    Description

    Step 1

    Make sure that clients use the current Intrusion Prevention policy

    The next time that the client receives the policy, the client applies the new custom signatures.

     

    Step 2

    Test the signature content on the client

    You should test the traffic that you want to block on the client computers.

    For example, if your custom IPS signatures should block MP3 files, try to download some MP3 files to the client computers. If the download does not occur, or times out after many tries, the custom IPS signature is successful.

    You can click Help for more information about the syntax that you can use in custom IPS signatures.

    Step 3

    View blocked events in Symantec Endpoint Protection Manager

    You can view events in the Network Threat Protection Attack logs. The message you specify in the custom IPS signature appears in the log.



  • 5.  RE: How to: Intrusion Prevention

    Posted Nov 25, 2011 06:06 AM

    Try a simulation of a ping flood attack:

    1. Make sure DoS detection is enabled in your IPS policy
    2. Send huge ping packets to a client (e.g., ping -l 50000 <IP address>)
    3. Client should announce DoS attack (and block communication with the "attacking" client by default for 10 minutes if Active Response is enabled)
    4. Check client security log.

    Of course this is just a test for a part of the IPS functionality.



  • 6.  RE: How to: Intrusion Prevention

    Posted Nov 25, 2011 06:58 AM

    Try and download EICAR from the EICAR website - it will trigger IPS



  • 7.  RE: How to: Intrusion Prevention

    Posted Nov 25, 2011 07:31 AM

    EICAR is a (static) virus signature checker. The asker is specifically asking for IPS.



  • 8.  RE: How to: Intrusion Prevention

    Posted Nov 25, 2011 07:46 AM

    I am well aware of what EICAR is.

    Trust me, try and download EICAR.COM from the EICAR.ORG website, it will trigger IPS BEFORE it triggers AV.