Hello all,
近期US-Cert發佈了SAP系統的一個新漏洞:
https://www.us-cert.gov/ncas/alerts/AA19-122A
有客戶詢問到Check Point如何進行防禦(How to Prevent);US-Cert已經先發佈了此攻擊相關的Snort Rule:
![SAP_Snort.png SAP_Snort.png](https://community.checkpoint.com/t5/image/serverpage/image-id/1131i3EB452F2AAC36B14/image-size/large?v=v2&px=999)
R80.10版本之後的客戶可以透過SmartConsole直接匯入來阻擋攻擊,步驟如下:
Step.1 將上方的Snort rule(可以在上方的US-Cert網頁複製)貼到記事本,並另存成 「XXX.rules」 Snort檔案格式。
![SAP_rules.png SAP_rules.png](https://community.checkpoint.com/t5/image/serverpage/image-id/1133iF8AFB1CFF402B885/image-size/large?v=v2&px=999)
Step.2 登入SmartConsole,切換到Security Policies頁籤,點選Threat Prevention policy,下方會有IPS Protectections的連結,點選上方的Action >> Snort Protections >> Import Snort rules >> 選擇剛剛另存的Snort rule:
![Import_Snort.png Import_Snort.png](https://community.checkpoint.com/t5/image/serverpage/image-id/1132i5FE128A33CB4D7C5/image-size/large?v=v2&px=999)
Step.3 匯入之後左下角Task會顯示匯入的進度:
![Import_Snort-2.png Import_Snort-2.png](https://community.checkpoint.com/t5/image/serverpage/image-id/1134i1D271C9AE1651393/image-size/large?v=v2&px=999)
Step.4 匯入完成之後,在IPS Protections裡面即可以查詢到剛剛匯入的Snort特徵碼:
![Import_Snort-3.png Import_Snort-3.png](https://community.checkpoint.com/t5/image/serverpage/image-id/1136iAF0935FD6DD85DD1/image-size/large?v=v2&px=999)
Step.5 進行Profile的設定之後就可以Install Policy開始進行防禦了。