- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: HTTP Inspection with personalized content filt...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HTTP Inspection with personalized content filter
Hi all,
we have some Microsoft packets coming form MS ISP IP addresses on HTTPS.
Those packets are originated by MS services for authentication purposes.
They are proxied through our firewall and forwarded to our onpremise federated auth infrastructure in dmz.
We receive both legitimate auth requests and brute force attacks.
The source IP addresses are ever trusted MS IPs and can not be filtered or dropped.
We would know if there is a way to enable https inspection inbound , parsing the content (the IP addreess inside the message) based on a list of IPs that we knows as malicius and we collect in other ways end finally prevent the packet from reaching the auth infrastructure
Only the checkpoint IPS IPs reputation may be not enough for us
(for now Microsoft says there is no ways for them to block those request......)
Many thanks 🙂
Rui
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How precisely is the IP encoded in the traffic?
If it's not in an IP or an HTTP header, it'll probably require an RFE.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, tks for your answer. Unfortunately inside the body message.
I suppose that a way must exist maybe in another blade like AV.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For Threat Prevention, you have the ability to create Snort Signatures.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi. Many thanks, I will check this feature (for me) unknown 🙂
Bye
