STIGQter STIGQter: STIG Summary: Juniper SRX SG IDPS Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 28 Jul 2017: The Juniper Networks SRX Series Gateway IDPS must generate an alert to, at a minimum, the ISSO and ISSM when root-level intrusion events that provide unauthorized privileged access are detected.

DISA Rule

SV-80917r1_rule

Vulnerability Number

V-66427

Group Title

SRG-NET-000392-IDPS-00216

Rule Version

JUSX-IP-000024

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure an attack group for "ROOT" attacks in the signature database which are recommended. Consult the Junos Security Intelligence Center IDP signatures website for a list and details of each attack, along with recommended action upon detection. Then add the attack group to a policy.

Specify the attack group as match criteria in an IDP policy rule.

Check Contents

Verify an attack group or rule is configured.

[edit]
show security idp policies

If an attack group or rules are not configured to detect root-level intrusion attacks or the match condition is not configured for an alert, this is a finding.

Vulnerability Number

V-66427

Documentable

False

Rule Version

JUSX-IP-000024

Severity Override Guidance

Verify an attack group or rule is configured.

[edit]
show security idp policies

If an attack group or rules are not configured to detect root-level intrusion attacks or the match condition is not configured for an alert, this is a finding.

Check Content Reference

M

Target Key

3037

Comments