Improve visibility of OT vulnerabilities and virtual patching signatures 7.4.2
This information is also available in the FortiOS 7.4 Administration Guide: |
The following improvements have been made in the GUI for the visibility of OT vulnerabilities and virtual patching signatures:
-
Add a Security Profiles > Virtual Patching Signatures page that displays all OT virtual patching signatures.
-
In the Assets widget (Dashboard > Assets & Identities), display a tooltip for detected IoT and OT vulnerabilities when hovering over the Vulnerabilities column.
-
Add the View IoT/OT Vulnerabilities option per device to drill down and list the IoT and OT vulnerabilities.
-
Display the OT Security Service entitlement status and OT package versions in the right-side gutter of a virtual patching profile page.
-
Display suggestions when creating a new virtual patching exemption.
Virtual Patching Signatures page:
In order to view the Virtual Patching and Virtual Patching Signatures pages, ensure that Virtual Patching is enabled on the System > Feature Visibility page.
The Virtual Patching Signatures page displays all OT virtual patching signatures. When using multi VDOM mode, the OT virtual patching signatures are displayed per VDOM.
Assets widget:
Hovering over the Vulnerabilities column displays a tooltip with a summary of FortiGuard detected IoT and OT vulnerabilities for the selected device.
Clicking View IoT/OT Vulnerabilities in the tooltip displays a list of vulnerabilities retrieved from the FortiGuard API server for the device. The OT Virtual Patching Signature column includes the virtual patch signature ID that is mapped to the Vulnerability ID.
License and entitlement information:
If a FortiGate does not have a valid OT license, a warning message is included in top of the IoT and OT vulnerabilities tooltip (Assets widget), indicating that OT vulnerabilities will not be detected.
The right-side gutter of virtual patching profile pages includes information about the following:
-
Operational Technology (OT) Security Service entitlement status
-
OT Detection Definitions Package version
-
OT Virtual Patching Signatures Package version
The System > FortiGuard page also includes the list of signatures under the Operational Technology (OT) Security Service entitlement.
Virtual patching exemptions:
When creating a new virtual patching exemption in a virtual patching profile, the Signature ID field includes a dropdown below it with suggestions (signature name and ID). Users can select a signature from the Suggestions dropdown or type in the Signature ID field to find a specific signature.