Anomaly Based Rules
Anomaly signatures based on time of day characteristics are implemented by configuring
schedulers using the Junos command ‘set schedulers’ and attaching them
to firewall policies, which in turn specify the target traffic in terms of IP addresses
and port numbers as well as the action to be perform on signature triggering (allow or
block/drop traffic).
Anomaly signatures based on throughput characteristics are implemented by configuring
policers with a bandwidth and burst size limit and the desired signature action (discard
or forward), using the Junos command ‘set firewall policer’, binding
them to firewall filters, and attaching the filter to any interface with the Junos
command ‘set interfaces’. Traffic exceeding the specified throughput
limit is dropped when the policer is configured to discard traffic.
A policer can be applied to specific inbound or outbound IP packets in a Layer 3 traffic flow at a logical interface by using a stateless firewall filter. If an input firewall filter is configured on the same logical interface as a policer, the policer is executed first. If an output firewall filter is configured on the same logical interface as a policer, the firewall filter is executed first.
Attack threshold-based filtering is set using rpm (real-time performance monitoring) probes, by configuring the threshold values and the traps to be generated.
Lastly, frequency-based filtering is set using counters that are defined within firewall filters to monitor the number of hits on the filter.
Configuration Examples
TOE detects and logs traffic matching the anomaly-based rules for a particular attribute.
Throughput:
set interfaces ge-1/0/1 vlan-tagging set interfaces ge-1/0/1 unit 0 vlan-id 900 set interfaces ge-1/0/1 unit 0 family inet filter input if_filter set interfaces ge-1/0/1 unit 0 family inet address 10.1.9.20/24 set interfaces ge-1/0/1 unit 0 family inet6 address 2001:10:1:9::20/64 set firewall family inet filter if_filter term allow from source-address 10.1.9.21/32 set firewall family inet filter if_filter term allow then policer policer-throughput set firewall family inet filter if_filter term allow then log set firewall family inet filter if_filter term allow then syslog set firewall family inet filter if_filter term allow then accept set firewall policer policer-throughput filter-specific set firewall policer policer-throughput if-exceeding bandwidth-limit 32k set firewall policer policer-throughput if-exceeding burst-size-limit 1500 set firewall policer policer-throughput then discard
Time of Day:
set security address-book book2 address address-sched 2001:10:1:9::21/128 set security policies from-zone trust to-zone untrust policy schedule match source-address address-sched set security policies from-zone trust to-zone untrust policy schedule match destination-address any set security policies from-zone trust to-zone untrust policy schedule then deny set security policies from-zone trust to-zone untrust policy schedule then log session-init set security policies from-zone trust to-zone untrust policy schedule then log session-close set security policies from-zone trust to-zone untrust policy schedule scheduler-name wed-schedule set security policies from-zone trust to-zone untrust policy vpn_bypass match source-address any set security policies from-zone trust to-zone untrust policy vpn_bypass match destination-address any set security policies from-zone trust to-zone untrust policy vpn_bypass match application any set security policies from-zone trust to-zone untrust policy vpn_bypass then permit set security policies from-zone trust to-zone untrust policy vpn_bypass then log session-init set security policies from-zone trust to-zone untrust policy vpn_bypass then log session-close
Frequency:
set interfaces ge-1/0/1 vlan-tagging set interfaces ge-1/0/1 unit 0 vlan-id 900 set interfaces ge-1/0/1 unit 0 family inet filter input TCP_Src_Port set interfaces ge-1/0/1 unit 0 family inet address 10.1.9.20/24 set interfaces ge-1/0/1 unit 0 family inet6 address 2001:10:1:9::20/64 set firewall family inet filter TCP_Src_Port term permit from protocol tcp set firewall family inet filter TCP_Src_Port term permit from source-port 1234 set firewall family inet filter TCP_Src_Port term permit then count TCP-count set firewall family inet filter TCP_Src_Port term permit then log set firewall family inet filter TCP_Src_Port term permit then syslog set firewall family inet filter TCP_Src_Port term permit then accept set firewall family inet filter TCP_Src_Port term implicit-deny then log set firewall family inet filter TCP_Src_Port term implicit-deny then discard
Threshold:
set services rpm probe owner test threshold-test target address 10.1.3.92 set services rpm probe owner test threshold-test thresholds rtt 50 set services rpm probe owner test threshold-test traps rtt-exceeded"