- play_arrow Overview
- play_arrow Juniper Advanced Threat Prevention Cloud Overview
- play_arrow Juniper Advanced Threat Cloud Prevention Setup
-
- play_arrow Juniper ATP Cloud Web Portal
- play_arrow Juniper ATP Cloud Web Portal Overview
-
- play_arrow Enroll SRX Series Firewalls in Juniper ATP Cloud Web Portal
- play_arrow Monitor Juniper ATP Cloud Features
- play_arrow Reports
- play_arrow Hosts
- play_arrow Identify Infected Hosts
- play_arrow Threat Sources
- play_arrow Identify Hosts Communicating with Command and Control Servers
- play_arrow IoT Device Discovery and Classification
- play_arrow Reverse Shell
- play_arrow Files
- play_arrow E-mails
- play_arrow Statistics
- play_arrow DNS
- play_arrow Encrypted Traffic Insights
-
- play_arrow Administration
- play_arrow Juniper ATP Cloud Administration
- Modify My Profile
- Create and Edit User Profiles
- Set Password
- Application Tokens Overview
- Create Application Tokens
- Multi-Factor Authentication Overview
- Configure Multi-Factor Authentication for Administrators
- Set Up Single Sign-on with SAML 2.0 Identity Provider
- Configure SSO Settings
- View Audit Logs
-
- play_arrow More Documentation
- play_arrow ATP Cloud Tech Library Page Links
-
Configure Threat Intelligence Sharing
Using the TAXII service, Juniper ATP Cloud can contribute to STIX reports by sharing the threat intelligence it gathers from file scanning. Juniper ATP Cloud also uses threat information from STIX reports as well as other sources for threat prevention. See HTTP File Download Details for more information on STIX reports.
STIX (Structured Threat Information eXpression) is a language used for reporting and sharing threat information using TAXII (Trusted Automated eXchange of Indicator Information). TAXII is the protocol for communication over HTTPS of threat information between parties.
STIX and TAXII are an open community-driven effort of specifications that assist with the automated exchange of threat information. This allows threat information to be represented in a standardized format for sharing.
If you enable TAXII (it is disabled by default), you can limit who has access to your shared threat information by creating an application token. See. Create Application Tokens.
To enable and configure threat intelligence sharing, do the following:
TAXII URLs and Services | Description |
---|---|
Discovery URL | Used by the TAXII client to discover available TAXII
Services. The command to initiate a TAXII request is: Note: For information about additional commands, see the TAXII documentation. Juniper ATP Cloud Discovery URLs are: US Region: https://taxii.sky.junipersecurity.net/services/discovery EU Region: https://taxii-eu.sky.junipersecurity.net/services/discovery APAC Region: https://taxii-apac.sky.junipersecurity.net/services/discovery Canada: https://taxii-canada.sky.junipersecurity.net/services/discovery |
At this time, there are two services supported by Juniper ATP Cloud on the TAXII server. | |
Collection Management | Used by the TAXII client to request information about available data collections. Juniper ATP Cloud Collection Management URLs are: US Region: https://taxii.sky.junipersecurity.net/services/collection-management EU Region: https://taxii-eu.sky.junipersecurity.net/services/collection-management APAC Region: https://taxii-apac.sky.junipersecurity.net/services/collection-management Canada: https://taxii-canada.sky.junipersecurity.net/services/collection-management |
Poll URL | Used by the TAXII client to poll for STIX files - looking for malware that has been identified on the network. Juniper ATP Cloud Polling URLs are: US Region: https://taxii.sky.junipersecurity.net/services/poll EU Region: https://taxii-eu.sky.junipersecurity.net/services/poll APAC Region: https://taxii-apac.sky.junipersecurity.net/services/poll Canada: https://taxii-canada.sky.junipersecurity.net/services/poll |