Botnet C&C signature blocking
To add IPS signatures to a sensor using the GUI:
One option is to use a predefined default IPS profile to block C&C Signatures. Default IPS profile is pre-configured with default action(block) for severity level 3, 4 and 5 which covers all the C&C signatures. |
- Go to Security Profiles > Intrusion Prevention.
- Edit an existing sensor, or create a new one.
- In the IPS Signatures and Filters section, click Create New.
- Set Type to Signature.
- Enter botnet in the Search field to get the list of all available signatures from the database.
- Right-click the signatures you want to include from the list.
- Click Add Selected.
- Configure the other settings as required.
- Click OK
- Configure other settings as required, then click OK
- Add this sensor to a firewall policy to detect or block attacks that match the IPS signatures.