Stop attempts to exploit system flaws or gain unauthorized access to
systems.
A Security rule can include the specification of a Vulnerability Protection
profile that determines the level of protection against buffer overflows, illegal
code execution, and other attempts to exploit system vulnerabilities. There are two
predefined profiles available for the Vulnerability Protection feature:
Customized profiles can be used to minimize vulnerability checking for traffic
between trusted security zones, and to maximize protection for traffic received from
untrusted zones, such as the internet, as well as the traffic sent to highly
sensitive destinations, such as server farms.
Apply a Vulnerability Protection profile to every Security rule that
allows traffic to protect against buffer overflows, illegal code execution, and
other attempts to exploit client- and server-side vulnerabilities.
The Rules settings specify collections of signatures to enable, as well as actions to
be taken when a signature within a collection is triggered.
The Exceptions settings allow you to change the response to a specific signature. For
example, you can block all packets that match a signature, except for the selected
one, which generates an alert. The Exception tab supports
filtering functions.
The Vulnerability Protection page presents a default set of
columns. Additional columns of information are available by using the column
chooser. Click the arrow to the right of a column header and select the columns from
the Columns sub-menu.
Follow these steps to configure a Vulnerability Protection profile.