Create an Infected Hosts Profile
You are here: Security Services > Advanced Threat Prevention > SecIntel Profiles.
Create an infected hosts profile to configure feeds and threat score to list the IP address or IP subnet of the compromised host. Infected hosts indicate local devices that are potentially compromised because they appear to be part of a C&C network or exhibit other symptoms.
To create an infected hosts profile:
-
Click Create > Infected Hosts on the
upper-right corner of the SecIntel Profiles page.
The Create Infected Hosts Profile page opens.
- Complete the configuration according to the guidelines provided in Table 1.
-
Click OK to save the changes. To discard your changes, click
Cancel.
Once you create the infected hosts profile, you can associate it with the SecIntel profile groups.
Table 1: Fields on the Create Infected Hosts Profile Page Field
Action
Name
Enter a name for the infected hosts profile.
The name must be a unique string of alphanumeric and special characters; 63-character maximum. Special characters such as < and > are not allowed.
Description
Enter a description for the infected hosts profile.
Default action for all feeds
Drag the slider to change the action to be taken for all the feed types. Actions are Permit (1 - 4), Log (5-6), and Block (7 - 10).
Log will have the permit action and also logs the event.
Feeds & threat score
Do the following:
-
Click + to define feeds and threat score to the infected hosts profile.
The Add Feeds window appears.
-
Enter the following details:
-
Feeds—Select one or more feeds from the Available column and move it to the Selected column to associate with the infected hosts profile.
-
Threat score—Drag the slider to change the action to be taken based on the threat score.
-
-
Click OK.
Block action
Select one of the following block actions from the list:
-
Drop Packets—Device silently drops the session’s packet and the session eventually times out.
-
Close session options—Device sends a TCP RST packet to the client and server and the session is dropped immediately.
Close session options
Select one of the following options from the list: None, Redirect URL, Redirect message, or File.
Redirect URL
Enter a remote file URL to redirect users when connections are closed.
Redirect message
Enter a custom message to send to the users when connections are closed.
Upload file
Click Browse to select and upload a file. This file is used to send to the users when connections are closed.
Note:The files must be in .php, .html, or .py format and will be stored in /jail/var/tm
-