Anomaly Based Rules

Anomaly signatures based on time of day characteristics are implemented by configuring schedulers using the Junos command ‘set schedulers’ and attaching them to firewall policies, which in turn specify the target traffic in terms of IP addresses and port numbers as well as the action to be perform on signature triggering (allow or block/drop traffic).

Anomaly signatures based on throughput characteristics are implemented by configuring policers with a bandwidth and burst size limit and the desired signature action (discard or forward), using the Junos command ‘set firewall policer’, binding them to firewall filters, and attaching the filter to any interface with the Junos command ‘set interfaces’. Traffic exceeding the specified throughput limit is dropped when the policer is configured to discard traffic.

A policer can be applied to specific inbound or outbound IP packets in a Layer 3 traffic flow at a logical interface by using a stateless firewall filter. If an input firewall filter is configured on the same logical interface as a policer, the policer is executed first. If an output firewall filter is configured on the same logical interface as a policer, the firewall filter is executed first.

Attack threshold-based filtering is set using rpm (real-time performance monitoring) probes, by configuring the threshold values and the traps to be generated.

Lastly, frequency-based filtering is set using counters that are defined within firewall filters to monitor the number of hits on the filter.

Configuration Examples

TOE detects and logs traffic matching the anomaly-based rules for a particular attribute.

Throughput:

Time of Day:

Frequency:

Threshold: