SV-80891r1_rule
V-66401
SRG-NET-000192-IDPS-00140
JUSX-IP-000007
CAT II
10
Create a protocol anomaly-based attack object:
Specify a name for the attack.
[edit]
security idp custom-attack anomaly1
Specify common properties for the attack.
[edit security idp custom-attack anomaly1]
set severity info
set time-binding scope peer count 2
Specify the attack type and test condition.
[edit]
security idp custom-attack anomaly1
set attack-type anomaly test OPTIONS_UNSUPPORTED
Specify other properties for the anomaly attack.
[edit]
security idp custom-attack anomaly1
set attack-type anomaly service TCP
u set attack-type anomaly direction any
attack-type anomaly shellcode spark
From operational mode, enter the following command to verify that the anomaly-based attack object was created.
show idp security policies
If anomaly-based attack objects are not created, bound to a zone, and active, this is a finding.
V-66401
False
JUSX-IP-000007
From operational mode, enter the following command to verify that the anomaly-based attack object was created.
show idp security policies
If anomaly-based attack objects are not created, bound to a zone, and active, this is a finding.
M
3037