bSecure Shared Objects & Threat Intelligence

A knowledge base article about bSecure Shared Objects & Threat Intelligence provided by the UC Berkeley IT Service Hub - Knowledge Portal

bSecure Shared Objects & Threat Intelligence

As part of the bSecure project, the Information Security Office (ISO) provides a number of firewall objects for departments to include in their individual security rules. This document outlines those objects and their appropriate use cases. Note: This document is updated periodically as shared objects change.

Address Objects

These objects can be used in the Source or Destination address fields of a security policy to either allow or deny access to specified campus IP ranges.

Object Name Description
ucbsec-vuln_scanners Represents the ISP vulnerability scanners. Use this as the source address in an "allow" rule. It is recommended not to attach Vulnerability Protection Profiles to these rules, as they may hamper detection.
UCB-networks_no_visitor A grouping of all campus network blocks, excluding the CalVisitor (open public Wi-Fi) subnets.
UCB-airbears2-eduroam A grouping of all network blocks associated with the Airbears and eduroam wireless services.
UCB-calvisitor Represents IP addresses associated with the CalVisitor wireless service. Commonly used in policies to deny access to resources that should not be public.
UCB-DHCP A grouping of the campus-operated DHCP servers.
UCB-DNS A grouping of both authoritative and caching DNS servers operated for the entire campus.
UCB-EOS-bigfix A grouping of the EOS-operated BigFix patch management servers.
UCB-VPN_All A grouping of all network blocks associated with all campus VPN services.
UCB-VPN_restricted A grouping of network blocks associated exclusively with the Restricted VPN service.
threat-AID_list IP addresses detected specifically attacking the campus network within the previous 24 hours.
threat-malicious_IPv4 A list of IPv4 addresses obtained from external threat intelligence performing malicious activities "in the wild."
threat-malicious_IPv6 A list of IPv6 addresses obtained from external threat intelligence performing malicious activities "in the wild."
Palo Alto Networks - High risk IP addresses High-risk IPs recently featured in threat activity advisories from high-trust organizations.
Palo Alto Networks - Known malicious IP addresses IPs used almost exclusively by malicious actors for malware distribution, command-and-control, or launching attacks.

URL Objects

These objects identify specific URLs distributing malware or used in phishing campaigns. They can be used in URL Filtering Profiles or as a URL Category in a deny policy. A URL Filtering Profile is generally the preferred option.

Object Name Description
ucbsec-URLs URLs populated by ISO for issues specifically targeting campus users, such as credential harvesting phishing campaigns.
threat-malicious_URLs A group of global malware and phishing URLs detected by external security partners.

Fully Qualified Domain Name (FQDN) Objects

These lists of FQDNs are used in Anti-Spyware Profiles within the DNS Signatures tab to block traffic to domains seen engaging in malicious activity.

Object Name Description
threat-malicious_FQDN A list of FQDNs obtained from external resources based on global malicious activity.

Accuracy of Shared Objects

Address objects representing campus-controlled networks (NOS or ISO) are highly accurate. For threat objects (including Palo Alto lists), there is a high level of confidence; however, some addresses may occasionally trigger based on activity that is research-oriented rather than malicious.

If you believe an address, domain, or URL is incorrectly included in these lists, please notify security-firewall@berkeley.edu.