A knowledge base article about bSecure Shared Objects & Threat Intelligence provided by the UC Berkeley IT Service Hub - Knowledge Portal
As part of the bSecure project, the Information Security Office (ISO) provides a number of firewall objects for departments to include in their individual security rules. This document outlines those objects and their appropriate use cases. Note: This document is updated periodically as shared objects change.
These objects can be used in the Source or Destination address fields of a security policy to either allow or deny access to specified campus IP ranges.
| Object Name | Description |
|---|---|
ucbsec-vuln_scanners |
Represents the ISP vulnerability scanners. Use this as the source address in an "allow" rule. It is recommended not to attach Vulnerability Protection Profiles to these rules, as they may hamper detection. |
UCB-networks_no_visitor |
A grouping of all campus network blocks, excluding the CalVisitor (open public Wi-Fi) subnets. |
UCB-airbears2-eduroam |
A grouping of all network blocks associated with the Airbears and eduroam wireless services. |
UCB-calvisitor |
Represents IP addresses associated with the CalVisitor wireless service. Commonly used in policies to deny access to resources that should not be public. |
UCB-DHCP |
A grouping of the campus-operated DHCP servers. |
UCB-DNS |
A grouping of both authoritative and caching DNS servers operated for the entire campus. |
UCB-EOS-bigfix |
A grouping of the EOS-operated BigFix patch management servers. |
UCB-VPN_All |
A grouping of all network blocks associated with all campus VPN services. |
UCB-VPN_restricted |
A grouping of network blocks associated exclusively with the Restricted VPN service. |
threat-AID_list |
IP addresses detected specifically attacking the campus network within the previous 24 hours. |
threat-malicious_IPv4 |
A list of IPv4 addresses obtained from external threat intelligence performing malicious activities "in the wild." |
threat-malicious_IPv6 |
A list of IPv6 addresses obtained from external threat intelligence performing malicious activities "in the wild." |
Palo Alto Networks - High risk IP addresses |
High-risk IPs recently featured in threat activity advisories from high-trust organizations. |
Palo Alto Networks - Known malicious IP addresses |
IPs used almost exclusively by malicious actors for malware distribution, command-and-control, or launching attacks. |
These objects identify specific URLs distributing malware or used in phishing campaigns. They can be used in URL Filtering Profiles or as a URL Category in a deny policy. A URL Filtering Profile is generally the preferred option.
| Object Name | Description |
|---|---|
ucbsec-URLs |
URLs populated by ISO for issues specifically targeting campus users, such as credential harvesting phishing campaigns. |
threat-malicious_URLs |
A group of global malware and phishing URLs detected by external security partners. |
These lists of FQDNs are used in Anti-Spyware Profiles within the DNS Signatures tab to block traffic to domains seen engaging in malicious activity.
| Object Name | Description |
|---|---|
threat-malicious_FQDN |
A list of FQDNs obtained from external resources based on global malicious activity. |
Address objects representing campus-controlled networks (NOS or ISO) are highly accurate. For threat objects (including Palo Alto lists), there is a high level of confidence; however, some addresses may occasionally trigger based on activity that is research-oriented rather than malicious.
If you believe an address, domain, or URL is incorrectly included in these lists, please notify security-firewall@berkeley.edu.