Learn how to operationalize network security with Strata Cloud Manager.
This example demonstrates how to manage and secure a large financial institution's global
network infrastructure using Strata Cloud Manager.
Day 3: Review Critical Security Alerts and Assess CVEs
Review Critical Security Alerts
Let’s consider some examples to review security alerts.
Anti-Spyware Profile Not Strict
This alert indicates that one of your Anti-spyware profiles isn't strict,
which could potentially allow spyware activity on the network. After
receiving this alert, your security team reviews the alert details. They
find that the alert is related to the security posture of their platform and
falls under the category of Malware Defenses. The alert suggests that to
prevent spyware activity on the network, they should clone the predefined
strict Anti-Spyware profile and retain the default “reset-both” Action for
critical, high, and medium severity levels.
Action: Clone and configure a strict profile to block spyware
effectively.
Application Not Set in Rule
This alert indicates that an application isn't set in a rule, which could
potentially allow unauthorized traffic through the firewall. However, upon
reviewing the alert, the security team realizes that this is due to a new
application that they are currently testing. They have intentionally not set
the application in a rule yet because they are still in the process of
evaluating the application's security.
Action: Temporarily suppress the alert if the application is under
evaluation. Revisit and configure the rule after completing testing.
Assess CVE Health
Navigate to
PAN-OS CVEs to see
the security advisories impacting your firewall. This information helps you decide
whether to upgrade a firewall based on the vulnerability and its impact on the
NGFW’s Health and Security.
For example, select a PAN-OS Known Vulnerability
(CVE-2021-44228) incident to see the security advisory on this CVE
impacting your firewall, and then navigate to Vulnerabilities Affecting
this Device Based on Enabled Features to view the affected features
for a vulnerability in the Feature Affected column. If a CVE
is not associated with a feature, then the value under Feature
Affected is empty.
You also select Vulnerabilities in this PAN-OS
version. This helps you decide whether to upgrade a firewall based
on the vulnerability and its impact beyond your enabled features. This type of CVE
affects the firewall with the specified model or version.
After understanding the vulnerabilities for impacted devices, you can plan
your patching using the Software Upgrade Recommendations
feature. View the Impacted Devices and
select firewalls that you want to upgrade to fix the vulnerabilities, and
Generate Upgrade Recommendations. You are redirected to
Software Upgrade Recommendations to view the generated
report.