<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic False positive with IPS and AntiBot? Confidence=HIGH, Medium in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/False-positive-with-IPS-and-AntiBot-Confidence-HIGH-Medium/m-p/84707#M3513</link>
    <description>&lt;P&gt;Appliance 1490, r77.20.87 Build 990172966&lt;BR /&gt;Blades: FW, AppCtrl, URLF, ABOT, AV, IPS, RAccs and SSL Inspect&lt;BR /&gt;Locally Managed&lt;BR /&gt;&lt;BR /&gt;1. Yesterday (2020-may-07) I did receive a notification in WachTower from FW about a BOT event.&lt;BR /&gt;2. Internal host suppostly infected was hostA&lt;BR /&gt;3. External threat host was 13.107.136.9&lt;BR /&gt;4. Reviewing logs I found communications attempts since May 7, logged by &lt;STRONG&gt;IPS&lt;/STRONG&gt; blade&lt;BR /&gt;5. Hours later, there is a log by &lt;STRONG&gt;AppCtrl&lt;/STRONG&gt; allow and identifying app &lt;STRONG&gt;Sharepoint-online&lt;/STRONG&gt; on ip 13.107.136.9, that's correct.&lt;BR /&gt;6. Then… was a log by &lt;STRONG&gt;Https Inspect&lt;/STRONG&gt; with a &lt;EM&gt;Revoked Certificate or invalid CRL&lt;/EM&gt; in connection to sharepoint.com (13.107.136.9).&lt;BR /&gt;7. Again others logs by IPS equal to point 4.&lt;BR /&gt;8. Yesterday (may-08) there is a log by &lt;STRONG&gt;AppCtrl&lt;/STRONG&gt; allowing &lt;STRONG&gt;eBay&lt;/STRONG&gt; app with traffic to ip 13.107.136.9!!!! &lt;STRONG&gt;What&lt;/STRONG&gt;? &lt;STRONG&gt;Resource&lt;/STRONG&gt; on such log can be readed as &lt;STRONG&gt;&lt;A href="https://hostXYZ.sharepoint.com/" target="_blank"&gt;https://hostXYZ.sharepoint.com/&lt;/A&gt;......&lt;/STRONG&gt; What was this confusion about? Or what am I misinterpreting? (Doubt )&lt;BR /&gt;9. After, there are logs by IPS and AppCtrl with same data.&lt;BR /&gt;10. Suddenly appear a log by &lt;STRONG&gt;ABot&lt;/STRONG&gt; with same resource of point 8 but identifying a client type &lt;STRONG&gt;MicrosoftSkydriveSync&lt;/STRONG&gt;.&lt;BR /&gt;11. Since then, there are logs by &lt;STRONG&gt;FW&lt;/STRONG&gt; blade. The strange thing about these logs is that despite the fact that the traffic originated from the internal host to the external one, it is the incoming rules that are generating it. (Doubt)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Why was the appliance confused in properly diagnosing the correct application (OneDrive, no eBay) and why did it take so long to do so? Is it a common latency?&lt;/P&gt;&lt;P&gt;Why a incoming rule do such logs (point 11) with connection traffic originated from internal host (outgoing traffic)?&lt;/P&gt;&lt;P&gt;Why IPS alerted with a confidence level HIGH detecting GBU BASH threat with HostA, but HostA is a Windows host?&lt;/P&gt;&lt;P&gt;I know, there are so much doubts, words and&amp;nbsp;lack of knowledge, I am reading guides but please, help me with this&amp;nbsp; issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm thinking about a false positive... but I don't be sure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="001-ips" style="width: 924px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6023iE6B10577E11AB367/image-size/large?v=v2&amp;amp;px=999" role="button" title="001-IPS.GIF" alt="001-ips" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;001-ips&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="002-AppC" style="width: 921px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6024i646355B025D2CFCF/image-size/large?v=v2&amp;amp;px=999" role="button" title="002-AppCtrl.GIF" alt="002-AppC" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;002-AppC&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="003" style="width: 920px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6026i9D23720D3382C410/image-size/large?v=v2&amp;amp;px=999" role="button" title="003-HTTPS Insp.GIF" alt="003" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;003&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="004-" style="width: 920px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6025iF1DE971F3EFC650B/image-size/large?v=v2&amp;amp;px=999" role="button" title="004-IPS.GIF" alt="004-" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;004-&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="005-AppC-eBay????" style="width: 923px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6027i4B442CA5AC905C44/image-size/large?v=v2&amp;amp;px=999" role="button" title="005-AppCtrl-eBay.GIF" alt="005-AppC-eBay????" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;005-AppC-eBay????&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="007-AppC-eBay again" style="width: 920px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6029i9EB26E99BAC42966/image-size/large?v=v2&amp;amp;px=999" role="button" title="007-AppCtrl-eBay.GIF" alt="007-AppC-eBay again" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;007-AppC-eBay again&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="008-ABot" style="width: 924px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6030i758E6209B3601BA0/image-size/large?v=v2&amp;amp;px=999" role="button" title="008-ABot-varias dudas.GIF" alt="008-ABot" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;008-ABot&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="009-outgoing traffice loggued by incoming rules?" style="width: 924px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6031i45A26E7C73CA52F2/image-size/large?v=v2&amp;amp;px=999" role="button" title="009-FW-reglas de entrada.GIF" alt="009-outgoing traffice loggued by incoming rules?" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;009-outgoing traffice loggued by incoming rules?&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="010-AppC bye eBay, now OneDrive" style="width: 917px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6032i85EBC43E0909D1E8/image-size/large?v=v2&amp;amp;px=999" role="button" title="010-AppCtrl-OneDrive.GIF" alt="010-AppC bye eBay, now OneDrive" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;010-AppC bye eBay, now OneDrive&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Notification of infection" style="width: 481px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6033i6DBEC582C83BDC83/image-size/large?v=v2&amp;amp;px=999" role="button" title="notificacionBOT.GIF" alt="Notification of infection" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Notification of infection&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 10 May 2020 02:35:15 GMT</pubDate>
    <dc:creator>LuisSP</dc:creator>
    <dc:date>2020-05-10T02:35:15Z</dc:date>
    <item>
      <title>False positive with IPS and AntiBot? Confidence=HIGH, Medium</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/False-positive-with-IPS-and-AntiBot-Confidence-HIGH-Medium/m-p/84707#M3513</link>
      <description>&lt;P&gt;Appliance 1490, r77.20.87 Build 990172966&lt;BR /&gt;Blades: FW, AppCtrl, URLF, ABOT, AV, IPS, RAccs and SSL Inspect&lt;BR /&gt;Locally Managed&lt;BR /&gt;&lt;BR /&gt;1. Yesterday (2020-may-07) I did receive a notification in WachTower from FW about a BOT event.&lt;BR /&gt;2. Internal host suppostly infected was hostA&lt;BR /&gt;3. External threat host was 13.107.136.9&lt;BR /&gt;4. Reviewing logs I found communications attempts since May 7, logged by &lt;STRONG&gt;IPS&lt;/STRONG&gt; blade&lt;BR /&gt;5. Hours later, there is a log by &lt;STRONG&gt;AppCtrl&lt;/STRONG&gt; allow and identifying app &lt;STRONG&gt;Sharepoint-online&lt;/STRONG&gt; on ip 13.107.136.9, that's correct.&lt;BR /&gt;6. Then… was a log by &lt;STRONG&gt;Https Inspect&lt;/STRONG&gt; with a &lt;EM&gt;Revoked Certificate or invalid CRL&lt;/EM&gt; in connection to sharepoint.com (13.107.136.9).&lt;BR /&gt;7. Again others logs by IPS equal to point 4.&lt;BR /&gt;8. Yesterday (may-08) there is a log by &lt;STRONG&gt;AppCtrl&lt;/STRONG&gt; allowing &lt;STRONG&gt;eBay&lt;/STRONG&gt; app with traffic to ip 13.107.136.9!!!! &lt;STRONG&gt;What&lt;/STRONG&gt;? &lt;STRONG&gt;Resource&lt;/STRONG&gt; on such log can be readed as &lt;STRONG&gt;&lt;A href="https://hostXYZ.sharepoint.com/" target="_blank"&gt;https://hostXYZ.sharepoint.com/&lt;/A&gt;......&lt;/STRONG&gt; What was this confusion about? Or what am I misinterpreting? (Doubt )&lt;BR /&gt;9. After, there are logs by IPS and AppCtrl with same data.&lt;BR /&gt;10. Suddenly appear a log by &lt;STRONG&gt;ABot&lt;/STRONG&gt; with same resource of point 8 but identifying a client type &lt;STRONG&gt;MicrosoftSkydriveSync&lt;/STRONG&gt;.&lt;BR /&gt;11. Since then, there are logs by &lt;STRONG&gt;FW&lt;/STRONG&gt; blade. The strange thing about these logs is that despite the fact that the traffic originated from the internal host to the external one, it is the incoming rules that are generating it. (Doubt)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Why was the appliance confused in properly diagnosing the correct application (OneDrive, no eBay) and why did it take so long to do so? Is it a common latency?&lt;/P&gt;&lt;P&gt;Why a incoming rule do such logs (point 11) with connection traffic originated from internal host (outgoing traffic)?&lt;/P&gt;&lt;P&gt;Why IPS alerted with a confidence level HIGH detecting GBU BASH threat with HostA, but HostA is a Windows host?&lt;/P&gt;&lt;P&gt;I know, there are so much doubts, words and&amp;nbsp;lack of knowledge, I am reading guides but please, help me with this&amp;nbsp; issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm thinking about a false positive... but I don't be sure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="001-ips" style="width: 924px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6023iE6B10577E11AB367/image-size/large?v=v2&amp;amp;px=999" role="button" title="001-IPS.GIF" alt="001-ips" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;001-ips&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="002-AppC" style="width: 921px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6024i646355B025D2CFCF/image-size/large?v=v2&amp;amp;px=999" role="button" title="002-AppCtrl.GIF" alt="002-AppC" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;002-AppC&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="003" style="width: 920px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6026i9D23720D3382C410/image-size/large?v=v2&amp;amp;px=999" role="button" title="003-HTTPS Insp.GIF" alt="003" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;003&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="004-" style="width: 920px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6025iF1DE971F3EFC650B/image-size/large?v=v2&amp;amp;px=999" role="button" title="004-IPS.GIF" alt="004-" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;004-&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="005-AppC-eBay????" style="width: 923px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6027i4B442CA5AC905C44/image-size/large?v=v2&amp;amp;px=999" role="button" title="005-AppCtrl-eBay.GIF" alt="005-AppC-eBay????" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;005-AppC-eBay????&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="007-AppC-eBay again" style="width: 920px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6029i9EB26E99BAC42966/image-size/large?v=v2&amp;amp;px=999" role="button" title="007-AppCtrl-eBay.GIF" alt="007-AppC-eBay again" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;007-AppC-eBay again&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="008-ABot" style="width: 924px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6030i758E6209B3601BA0/image-size/large?v=v2&amp;amp;px=999" role="button" title="008-ABot-varias dudas.GIF" alt="008-ABot" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;008-ABot&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="009-outgoing traffice loggued by incoming rules?" style="width: 924px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6031i45A26E7C73CA52F2/image-size/large?v=v2&amp;amp;px=999" role="button" title="009-FW-reglas de entrada.GIF" alt="009-outgoing traffice loggued by incoming rules?" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;009-outgoing traffice loggued by incoming rules?&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="010-AppC bye eBay, now OneDrive" style="width: 917px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6032i85EBC43E0909D1E8/image-size/large?v=v2&amp;amp;px=999" role="button" title="010-AppCtrl-OneDrive.GIF" alt="010-AppC bye eBay, now OneDrive" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;010-AppC bye eBay, now OneDrive&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Notification of infection" style="width: 481px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6033i6DBEC582C83BDC83/image-size/large?v=v2&amp;amp;px=999" role="button" title="notificacionBOT.GIF" alt="Notification of infection" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Notification of infection&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 May 2020 02:35:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/False-positive-with-IPS-and-AntiBot-Confidence-HIGH-Medium/m-p/84707#M3513</guid>
      <dc:creator>LuisSP</dc:creator>
      <dc:date>2020-05-10T02:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: False positive with IPS and AntiBot? Confidence=HIGH, Medium</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/False-positive-with-IPS-and-AntiBot-Confidence-HIGH-Medium/m-p/84732#M3514</link>
      <description>False positives do happen from time to time.&lt;BR /&gt;Best to engage the TAC here so we can understand (and fix).</description>
      <pubDate>Sun, 10 May 2020 15:01:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/False-positive-with-IPS-and-AntiBot-Confidence-HIGH-Medium/m-p/84732#M3514</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-10T15:01:43Z</dc:date>
    </item>
  </channel>
</rss>

