Table of Contents
Overview
The Information Security Office (ISO) provides several security profiles for departments to utilize in their local firewall environments. To evaluate these for your unit, it is best to review the internal settings within Panorama. The steps below describe how to examine Antivirus profiles.
How to Examine Antivirus Profiles
- Log into https://panorama.net.berkeley.edu using single sign-on.
- Select the Objects tab from the top navigation bar.
- Under the Security Profiles menu in the left pane, select Antivirus.
- ISO has developed two primary Antivirus profiles for campus use:
ucbsec-standardanducbsec-alerting.
Protocol Decoders and Actions
By opening a profile (e.g., ucbsec-standard), you can view the list of protocols the firewall can decode to examine for malicious files. You can also see the Action taken if a virus is detected via standard signatures or WildFire appliances.
Technical Note (POP3 and IMAP): For email protocols like POP3 and IMAP, the actions are always set to Alert. This is because attempting to kill the connection (Reset) would cause the client to immediately retry the transfer, creating an infinite loop. Additionally, blocking these connections would prevent the user from seeing any legitimate emails received after the malicious message.
Exceptions
There are two types of exceptions in an Antivirus profile. Note that ucbsec-standard does not contain exceptions as it applies campus-wide, but you may need these for custom departmental profiles:
A. Application Exceptions
Used when a specific application (identified by App-ID) requires different behavior even if it uses a standard protocol. For example, WebDAV might require an exception while operating over HTTP.
B. Virus Exceptions
Used if a specific virus behavior is being misidentified (false positive) or if a researcher needs to allow a specific threat for analysis. For example, allowing Def.Gen Command And Control Traffic.
Additional Resources
For more details, visit the vendor documentation: Antivirus Security Profile Documentation.