Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
WiliRGasparetto
MVP Diamond
MVP Diamond

Technical Deep Dive Why Maintain Both Normal and V2 IPS Signatures in Check Point?

Check Point’s Intrusion Prevention System (IPS) is a core component of Threat Prevention, providing proactive protection against a wide range of network threats. Over time, the IPS engine and its signature formats have evolved, leading to the coexistence of "normal" and "version 2 (Ver 2)" signatures. This post explains the technical reasons for maintaining both, their architectural differences, and best practices for deployment.

IPS Architecture Overview

Check Point IPS uses a multi-layered detection engine:

  • Passive Streaming Library (PSL): Reconstructs network streams for inspection.
  • Protocol Parsers: Identify and separate protocols (HTTP, FTP, DNS, etc.) for context-aware analysis.
  • Context Management Infrastructure (CMI): Determines which protections (signatures) apply to each protocol context.
  • Pattern Matcher: The detection engine that uses signatures to identify malicious patterns.

IPS Inspection Flow Diagram

WiliRGasparetto_0-1773790826936.jpeg

 

Traffic is processed through multiple analysis stages, with signatures applied at different protocol layers.

 

 

Normal vs. V2 Signatures: Technical Comparison

Feature Normal Signature V2 Signature (INSPECTv2)
Detection Engine Classic Pattern Matcher INSPECTv2 (advanced engine)
Coverage Known threats New threats, evasive techniques, improved accuracy
Performance Lower resource usage May require more CPU/memory, but optimized for accuracy
Compatibility Legacy gateways Modern gateways (R80+)
Update Frequency Less frequent Updated regularly
  • Normal Signatures: Use traditional pattern matching, suitable for legacy environments and lower resource consumption.

 

  • V2 Signatures: Leverage the advanced INSPECTv2 engine, supporting complex logic, context awareness, and better detection of modern threats.

 

Why Maintain Both Signature Types?

  • Backward Compatibility: Some older gateways may not support V2 signatures. Keeping both ensures all devices remain protected.
  • Redundancy: If a V2 signature causes issues (e.g., false positives), the normal signature can provide fallback protection.
  • Gradual Migration: Allows administrators to test V2 signatures in "Detect" mode before fully switching from normal signatures.
  • Maximum Coverage: Certain threats may only be detected by one signature type, so using both maximizes security.

 

Performance Considerations

  • V2 signatures can be more resource-intensive due to deeper inspection and advanced logic.
  • IPS Tuning: Administrators can enable/disable specific signatures or use different profiles for perimeter vs. internal gateways.
  • Bypass Under Load: IPS can be configured to bypass traffic during high load to prevent bottlenecks, but this should be used cautiously.

 

Best Practices for Managing Signature Versions

  1. Test in Staging: Always test new V2 signatures in a non-production environment.
  2. Monitor Updates: Review IPS update notes and apply urgent protections as needed.
  3. Separate Profiles: Use different IPS profiles for different gateway roles (e.g., perimeter vs. datacenter).
  4. Monitor Logs: Watch for false positives/negatives and adjust protections accordingly.
  5. Gradual Rollout: Deploy V2 signatures in "Detect" mode before moving to "Prevent."

 

Summary

  • Normal signatures ensure compatibility and stability.
  • V2 signatures provide enhanced detection and future-proofing.
  • Maintaining both allows for a safe, flexible, and comprehensive security posture during transitions and upgrades.

 

References

(2)
47 Replies
WiliRGasparetto
MVP Diamond
MVP Diamond

The way to search for subscriptions without needing a special login

https://advisories.checkpoint.com/advisories/

https://advisories.checkpoint.com/advisories/

AlbertoThree
Participant

So if IPS Explorer is not available, what other means do we have to find out the exact pattern the IPS protection matched on?

PhoneBoy
Admin
Admin

To my knowledge, there is no way to see what a given IPS signature matches.

WiliRGasparetto
MVP Diamond
MVP Diamond

Hi @AlbertoThree , sorry for the delay in responding, but I found a website where we can verify the signatures and what they protect. Here are the links.

https://advisories.checkpoint.com/advisories/

https://threatwiki.checkpoint.com/threatwiki/public.htm

AlbertoThree
Participant

Thanks for the info!

WiliRGasparetto
MVP Diamond
MVP Diamond

You're welcome, we're here to help each other. Actually, I wrote another article on how to do this research; here's the link.

https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-Signature-Evidence-the-shor...

WiliRGasparetto
MVP Diamond
MVP Diamond

I think this is totally on topic, @AlbertoThree , as @Timothy_Hall  said, you need a screenshot of the video to see more details. You can add them here, like in the screenshot.

 

ips tim.png

AlbertoThree
Participant

Thanks @WiliRGasparetto and @WiliRGasparetto for your answers!
As soon as I am back in the office I will take a look at IPS explorer as well as review the settings.

0 Kudos
WiliRGasparetto
MVP Diamond
MVP Diamond

You're welcome, count on us anytime for this and other matters.

WiliRGasparetto
MVP Diamond
MVP Diamond

I wrote another article related to EPS troubleshooting; it's worth reading at the link.

https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-How-to-Filter-Events-by-CVE...

WiliRGasparetto
MVP Diamond
MVP Diamond

Hi everyone, I found where to search for subscriptions and wrote an article about it.

https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-Signature-Evidence-the-shor...

Jeromvdhoek1986
MVP Diamond
MVP Diamond

Very nice post indeed

WiliRGasparetto
MVP Diamond
MVP Diamond

Thank you

Mark89
Explorer

From an operational perspective, how can administrators verify in SmartConsole or IPS logs whether a connection was evaluated by the classic Pattern Matcher or by INSPECTv2, and how can they objectively measure the additional detection benefit versus the performance cost of keeping both protection variants enabled?

0 Kudos
WiliRGasparetto
MVP Diamond
MVP Diamond

Currently, standard SmartConsole and IPS logs do not directly indicate whether a connection was processed by the classic Pattern Matcher or by INSPECTv2. The inspection process is internal to the IPS engine, and the log shows only which protection was triggered, not the exact mechanism used.

0 Kudos
jorgeluiznim
Advisor

Excellent post! Really clear and well structured.

I loved how you covered the gradual transition using Detect mode and outlined those best practices. It adds a ton of practical value for anyone managing IPS on a daily basis. Thanks for sharing!

WiliRGasparetto
MVP Diamond
MVP Diamond

Thank You

0 Kudos
WiliRGasparetto
MVP Diamond
MVP Diamond

Yor Welcome

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events