SYMP-AG-000670 - Symantec ProxySG providing content filtering must generate an alert to, at a minimum, the ISSO and ISSM when denial-of-service (DoS) incidents are detected - Client limits

Information

Without an alert, security personnel may be unaware of major detection incidents that require immediate action, and this delay may result in the loss or compromise of information.

The ALG generates an alert that notifies designated personnel of the Indicators of Compromise (IOCs) that require real-time alerts. These messages should include a severity level indicator or code as an indicator of the criticality of the incident. These indicators reflect the occurrence of a compromise or a potential compromise. Since these incidents require immediate action, these messages are assigned a critical or level 1 priority/severity, depending on the system's priority schema.

CJCSM 6510.01B, 'Cyber Incident Handling Program', lists nine Cyber Incident and Reportable Event categories. DoD has determined that categories identified by CJCSM 6510.01B Major Indicators (category 1, 2, 4, or 7 detection events) will require an alert when an event is detected.

Alerts may be transmitted, for example, telephonically, by electronic mail messages, or by text messaging. The ALG must either send the alert to a management console that is actively monitored by authorized personnel or use a messaging capability to send the alert directly to designated personnel.

Solution

Configure the ProxySG to email DoS attack detection/mitigation alerts to the ISSO and ISSM.

1. SSH into the ProxySG console and type 'enable'.
2. Enter the correct password and type 'config'.
3. Press 'Enter' and type 'attack-detection'.
4. See the ProxySG Administration Guide, Chapter 73: Preventing Denial of Service Attacks, to understand the functionality before proceeding.
5. Type 'client' and press 'Enter'. Type 'enable-limits' and press 'Enter'.
6. Log on to the Web Management Console.
7. Browse to Maintenance >> Event Logging and click the 'Mail' tab. Ensure that the ISSO and ISSM email addresses are specified.
8. Browse to Configuration >> Policy >> Visual Policy Manager. Click 'Launch'.
9. In one Web Access Layer, create a new rule. Right-click the 'Action' of that rule and select 'Set'. Click 'New' and select 'Set Attack Detection'. Provide a 'Failure Weight' per local security policy requirements.
10. Click 'OK' and click 'OK' again.
11. Right-click the 'Track' column for this rule and select 'Set'. Click 'New' and select 'Email'.
12. Select 'Custom Recipients' and click 'Configure Custom Recipients Lists'.
13. Click 'New,' provide a name for the list, and enter the ISSO and ISSM email addresses in the 'List Members' field.
14. Click 'OK' and click 'OK' again. Create message text and click 'OK'.
15. Click 'OK' and click 'OK' again. Select File >> Install Policy on SG Appliance.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SYM_ProxySG_Y20M04_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4(5), CAT|II, CCI|CCI-002664, Rule-ID|SV-104301r1_rule, STIG-ID|SYMP-AG-000670, Vuln-ID|V-94347

Plugin: BlueCoat

Control ID: ee3e0a4391282548e35f8a84c313cf254f543b694e1c3f40769a89ebed62dbfc