DefensePro User Guide
Security Configuration
Document ID: RDWR-DP-V0602_UG1201
149
Configuring Signature Protection for Network Protection
Note:
Signature Protection is not available in DefensePro models running on the OnDemand
Switch 3 S1 platform.
Signature Protection detects and prevents network-oriented attacks, Operation System (OS)
oriented attacks and application-oriented attacks by comparing each packet to the set of signatures
stored in the Signatures database.
The attacks handled by this protection can be divided into the following groups:
•
Server-based vulnerabilities:
—
Web vulnerabilities
—
Mail server vulnerabilities
—
FTP server vulnerabilities
—
SQL server vulnerabilities
—
DNS server vulnerabilities
—
SIP server vulnerabilities
•
Worms and viruses
•
Trojans and backdoors
•
Client-side vulnerabilities
•
IRC bots
•
Spyware
•
Phishing
•
Anonymizers
Configuration Considerations with Signature Protection
You can configure Signature Protection using Radware Security Operations Center (SOC) signature
profiles or using user-defined signature profiles.
Radware recommends that you configure policies containing Signature Protection profiles using
Networks with Source = Any, the public network, and Destination = Protected Network. You can
configure policies to use VLAN tags, application ports, physical ports, and MPLS RDs.
For implications of direction settings for rules and protections, see
Table 77 - Implications of Policy
Policies containing Signature Protection profiles can be configured with Direction set to either One
Way or Two Way.
Protections can be configured with the Direction values Inbound, Outbound, or In-Outbound.
While most of the attacks (such as worm infections) are detected through their inbound pattern,
some attacks require inspecting outbound patterns initiated by infected hosts. For example, trojans
require inspecting outbound patterns initiated by infected hosts.
Policies configured with Source = Any and Destination = Any inspect only In-Outbound attacks.
Radware provides you with a set of predefined signature profiles for field installation, such as
Corporate Gateway, DMZ and LAN protections, Carrier links protections, and so on. Radware profiles
are continuously updated along with the weekly signature database maintained by the Radware
SOC. You cannot edit Radware signature profiles.
Summary of Contents for DefensePro 6.02
Page 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Page 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Page 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Page 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Page 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Page 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Page 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Page 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...