SV-80909r1_rule
V-66419
SRG-NET-000362-IDPS-00196
JUSX-IP-000017
CAT II
10
Create a protocol anomaly-based attack object:
Specify a name for the attack.
[edit]
security idp custom-attack anomaly1
Specify common properties for the attack.
[edit security idp custom-attack anomaly1]
set severity info
set time-binding scope peer count 2
Specify the attack type and test condition.
[edit]
security idp custom-attack anomaly1set attack-type anomaly test OPTIONS_UNSUPPORTED
Specify other properties for the anomaly attack.
[edit]
security idp custom-attack anomaly1]
set attack-type anomaly service TCP
u set attack-type anomaly direction any
attack-type anomaly shellcode spark
From operational mode, enter the following command to verify that the anomaly-based attack object was created:
show idp security policies
If anomaly-based attack objects are not created, bound to a zone, and active, this is a finding.
V-66419
False
JUSX-IP-000017
From operational mode, enter the following command to verify that the anomaly-based attack object was created:
show idp security policies
If anomaly-based attack objects are not created, bound to a zone, and active, this is a finding.
M
3037