A known, confirmed attack Detected when a file or traffic matches a signature pattern: 1- lPS signatures 2- WAF signatures 3- Antivirus signatures Example: Exploit of known application vulnerabilities
Exploit
Anomaly
Can be zero-day or denial of service attacks (DoS) Detected by behavioral analysis: 1-Rate-based IPS signatures 2-DoS policies 3-Protocol constraints inspection Example: Abnormally high rate of traffic (DoS/flood)
Flow-based detection and blocking :
Known exploits that match signatures Network errors and protocol anomalies
Known exploits and protocol anomalies Network errors that match signatures
IPS Components‘ IPS signature databases ‘ Protocol decoders IPS engine (Select 3)
IPS signature databases
Protocol decoders
IPS engine
IPS Protocol decoders
IPS engine databases
IPS engine (Select 5)
Application control
Anti-virus (flow based)
Web filter (flow based)
Email filter (flow based)
Data Leak Prevention (DLP) (flow based in one-arm sniffer mode)
Anti-virus (flow based in one-arm sniffer mode)
IPS (flow based)
Anti-spam (flow based)
Decoders parse protocols. lPS signatures find parts of a protocol that don’t conform. For example, too many HTTP headers, or a buffer overflow attempt Unlike proxy-based scans, IPS often does not require IANA standard ports. Automatically selects decoder for protocol at each OSI layer
What Are Protocol Decoders?
What Are Protocol?
What Are Decoders?
IPS packages are updated by FortiGuard. (Select 3)
IPS Protocol
IPS databases
IPS signature
Choosing the Signature Database - ❌ : Common attacks with fast, certain identification (default action is block)
- ❌ : Performance-intensive
In fact, because of its size, the extended database is only available for FortiGate models with a smaller disk or RAM. But, for high-security networks, you might be required to enable the extended signatures database.
Configuring IPS sensors
Two ways: Add signatures Add filters
Three ways: Add signatures Add filters Add IPS profile in the policy
IPS Actions (Select 6)
Pass
Monitor
Warning
Block
Reset
Default
Packet Logging
Quarantine
Which of the following are evaluated first in an lPS sensor?
A. IPS filter
B. IPS signature
Which IPS component is updated most frequently?
A. Protocol decoders
B. IPS signature database