Examining an Antivirus profiles

A knowledge base article about Examining an Antivirus profiles provided by the UC Berkeley IT Service Hub - Knowledge Portal

Information Security Office (ISO) create a number of security profiles that individual departments can use in their own environment. In order to understand the settings associated with these profiles and to evaluate them for local use, it is best to review the profiles is by looking at the settings themselves. Below are the steps that would be necessary to examine the settings of a Antivirus profiles.

  1.  While logged into https://panorama.net.berkeley.edu, chose “Objects” from the tabs at the top of the window
  2. Under “Security Profiles” in the left pane choose “Antivirus”
  3. Unlike most other Security Profiles, there are just two Antivirus profiles that were developed by ISP; ucbsec-standard and ucbsec-alerting.
  4. By opening up one of these profiles (in this case the ucbsec-standard profile) You can see the list of protocols the Palo Alto firewall is able to decode and examine for files containing a virus, as well as the action it will take if it detects a virus with its normal antivirus signatures and signatures generated from our on campus WildFire appliances.

    In reviewing these settings something to keep in mind is that for pop3 and imap the nature of the protocols is such that if we try to kill the connection by sending a reset packet to both the client and the server, the next time the client tries to connect it will try to send that file again and this processes will be repeated over and over again. Additionally, because of the way the files and messages are transferred on these protocols, the client will not see any email that was received after the offending message/file. This is why it is important that for pop3 and imap, the actions are always alert.
  5. After reviewing the rules, it is important to examine exceptions to the normal configuration. In an Antivirus profile, there are two places an exception can be made; the first is for applications that sit on top of one of the decoders and the second is exceptions for individual virus types. In the ucbsec-standard Antivirus profile there should not be any exceptions because this exception would apply to the entire campus. However, for the purposes of this article, two exceptions are being shown so that it will be clear what they would look like if someone needed to create a custom Antivirus profile.
     
    1. Application Exceptions are made if its necessary to have a different behaviour if an application (identified by App-ID) is the one being used. In this example the exception would be for webdav which operates over the http protocol and would be subject to the rules of that decoder.
    2. If instead of a protocol, there a file or virus behavior is being misidentified (or perhaps there is an actual virus that is being used by a researcher for analysis) and it needs to be allowed, the exception would be under the “Virus Exception” tab. In this example the “Def.Gen Command And Control Traffic” is being allowed.

  6. Once the Antivirus profile is understood, it is possible to exit these screens by clicking the “Cancel” button.



More information about Antivirus profiles can be found at:
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/objects/objects-security-profiles-antivirus