Information Security and Policy (ISP) create a number of security profiles that individual departments can use in their own environment. In order to understand the settings associated with these profiles and to evaluate them for local use, it is best to review the profiles is by looking at the settings themselves. Below are the steps that would be necessary to examine the settings of a WildFire Analysis profiles.
- While logged into https://panorama.net.berkeley.edu, chose “Objects” from the tabs at the top of the window
- Under “Security Profiles” in the left pane choose “WildFire Analysis”
- Unlike most other Security Profiles, there are just two WildFire Analysis profiles that were developed by ISP; ucbsec-hybrid_cloud and ucbsec-on_prem_cloud_only.
- Of these two profiles, the recommended profile is ucbsec-on_prem_cloud_only. The reason this is recommended is that WildFire is a product that attempts to determine if a file is malicious by running it in a sandbox environment and seeing if any malicious activity is detected. For profiles that utilize Palo Alto’s public cloud, the file (if its one of the recognized file types that can be tested in this fashion) is uploaded to a system managed by Palo Alto. This means that if the file contains sensitive or proprietary information that information is also sent to Palo Alto. This does come with the drawback that the file types that can be tested on campus are a subset of the those handled by the public cloud. So if a department does not have, send or receive any sensitive data but receives files not covered by the on-premise solution they may want to consider changing to the ucbsec-hybrid_cloud profile which analyzes the files locally when it can, and sends any it can’t to Palo Alto.
- The settings for the ucbsec-on_prem_cloud_only profile are to send the file types listed in the “File Types” column to our onsite WildFire Appliances (private-cloud) without regard to the application the files were sent on and the direction they were sent. Like firewall rules, the rules in a Wildfire Analysis Profile are read top to bottom so the first rule that matches the file type (along with any other criteria) would be the one used.
If someone wanted to write a custom WildFire Analysis profile, it is possible to designate the application the transfer used (based upon the Palo Alto detected AppID) or the direction of the file (upload or download) as part of the match behavior.- For example, if a researcher regularly downloaded malicious files from a git repository, then it would be possible to create a rule to ignore traffic of that type. And then a second rule that still performs the WildFire analysis for any file types seen in another way. In this scenario, it would be best to create a unique WildFire profile and apply it to a rule just for that traffic.
- Once the Wildfire Analysis profile is understood, it is possible to exit these screens by clicking the “Cancel” button.
More information about Wildfire Analysis profiles can be found at:
https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/objects/objects-security-profiles-wildfire-analysis