Examining a Vulnerability Protection profile

A knowledge base article about Examining a Vulnerability Protection profile provided by the UC Berkeley IT Service Hub - Knowledge Portal

Information Security Office (ISO) create a number of security profiles that individual departments can use in their own environment. In order to understand the settings associated with these profiles and to evaluate them for local use, it is best to review the profiles is by looking at the settings themselves. Below are the steps that would be necessary to examine the settings of a vulnerability profile.

  1.  Log into https://panorama.net.berkeley.edu using single sign-on
  2. From the tabs at the top of the window chose “Objects”
  3. Under “Security Profiles” in the left pane choose “Vulnerability Protection”
  4. From the list of Vulnerability Protection profiles select the one that you are interested in examining. For this example we will look at the ucbsec-RD_server (this is the recommended Vulnerability Protection profile for servers containing Restricted Data). Opening the profile, the first thing you will notice is the rules. Like firewall rules in general, these rules are read by the Palo Alto firewall in order from top down.
  5. The first rule, “simple-server-critical,” will apply to any threat where the vulnerability is a part of any category, is directed toward the server (as compared to a client exploit), and has a severity (as determined by Palo Alto) of critical. If an attack that matches this criteria is detected, it will take the action described in the action column, which in this case is send a reset-packet to both the client and the server. Effectively, this ends the session. It will also records the packet that that was detected attempting the exploit. If your display does not contain the Category column, click on the down arrow that appears if you hover over a column header and then from the resulting menu, choose “Columns” and “Category”
  6. The next rule, “simple-client-critical,” performs a similar function with the intended victim being the client.
  7. This pattern continues on with lower levels of severity until the “Detect Brute Force” vulnerability rule.

    For this rule, the severity is set to any, however, because it is lower than the critical and high severity rules above, it will not be used if the vulnerability has been assigned one of those severities. It will, however, take precedence over any lower rules. Additionally, it only applies to rules that are in the category of brute-force. When it detects something that meets this criteria it does not block it but generates an alert and captures the packet as well as any others it can in related to this issue.
  8. After reviewing the rules, it is important to examine the exceptions to the rules. In the ucbsec-RD_server Vulnerability Protection profile, there are 4 exceptions. These exceptions were made because the action assigned to that threat in the Rules was not an appropriate action for our environment.
  9. In this example there, the exception for “Glibc getaddrinfo Buffer Overflow Vulnerability”  has the number 4 next to it. That is the number of IPs that this exception applies to and if there is no number then it is an across the board exception. If you click on the number 4 in this example, a window will pop up showing you the IPs that this exception applies to.
  10. To exit out of this, click the “Cancel” button for the ‘IP address Exemptions” (if necessary) and the “Vulnerability Protection Profile” windows.

More information about Vulnerability Protection profiles can be found at:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-security-profiles-vulnerability-protection