Endpoint Protection

 View Only
  • 1.  IPS DoS when adding remote printer

    Posted Dec 01, 2010 09:18 AM

     

    seclog.log entry when creating printer on remote pc:

    "Denial of Service "UDP Flood Attack" attack detected.
    Description:

     An excessive number of User Datagram Protocol (UDP) packets are being generated on this computer causing 100% CPU utilization..  "

    steps to reproduce:

    windows explorer - \\machinename - view remote printers - add a printer

    -add local printer - standard TCP/IP port - enter printer dns name

    at this point, it will usually fail to resolve the printer and get pop-up that traffic to the printer is now being blocked b/c of DOS.  

    Windows 7 32x, occurs on both 11.06a and 11.06mp1.  IPS working as designed?



  • 2.  RE: IPS DoS when adding remote printer

    Posted Dec 01, 2010 09:42 AM

    Exact same issue I had with a user when they went off the corporate network and tried to connect to their wireless printer. I also thought it was resolved in RU6 MP1 per the release note below but it still occurs. It occurred on RU6a as well.

    An unexpected UDP flood attack is reported after upgrading to RU6
    Fix ID: 2038207
    Symptom: An unexpected UDP flood attack is reported after upgrading to RU6, and blocks what appears to be a legitimate internal DNS server.
    Solution: Symantec Endpoint Protection client was updated to verify that the DNS response packet comes from a valid DNS server.

     

     

    What I ended up doing was going into the IPS policy >> Settings >> Enable excluded hosts and added the IP of the printer.

    Seems to be working fine now



  • 3.  RE: IPS DoS when adding remote printer

    Posted Dec 01, 2010 10:57 AM

     

    @Brian81,
     
    The defect you listed was in regards to SEP misidentifying UDP traffic from a DNS server to be a UDP flood. Whatever changes were implemented to address the issue in RU6 MP1 were made to address this issue in regards to DNS servers specifically and were not made to address any UDP flood false positive detections which might occur from network printers.
     
    @kornholio,
     
    I've seen situations before where printers will trigger Denial of Service rules in SEP even when they are working normally. The printers just happen to communicate in a way which triggers our DoS rules.
     
    A good short-term solution would be, as Brian81 suggested, to add the printer to the list of excluded hosts. Admittedly, the chances of your printer sending out malicious traffic or being infected is very small, but best practices would have you only exclude the printer if you know that the traffic from the printer is non-malicious.
     
    Unfortunately, determining whether or not the traffic is malicious is not something I can assist with as I do not have the means to know what normal printer traffic for your printer should look like. You may consider gathering a packet capture of the traffic which is triggering the DoS detection and opening a support ticket with the maker of the printer in order to determine if the traffic is malicious. If it is not malicious, exclude the printer as a workaround. You could then open a Symantec Support ticket if you wanted to have us analyze the traffic to determine if we need to change our UDP Flood DoS rules.
     
    Regards,
     
    James


  • 4.  RE: IPS DoS when adding remote printer

    Posted Dec 01, 2010 11:23 AM

    thanks for the responses....I was really hoping to confirm that this wasn't part of the DNS bug, which it sounds like it is not.  So we will look at adding IPs to the exclusions as a work-around. 



  • 5.  RE: IPS DoS when adding remote printer

    Posted Dec 01, 2010 11:36 AM

    Thanks James,

    I kinda figured they were separate.

    For now, I added the IP to the exclusion list. This appears to be a one time issue for me so I'm not going to worry about it, especially with it being a user off the network. On the network would be a different story.



  • 6.  RE: IPS DoS when adding remote printer

    Posted Dec 18, 2010 09:21 PM

    I'm having the same issue but have no idea how to get to "IPS policy >> Settings >> Enable excluded hosts" to make this change.  Please tell me where to find IPS policy.  I've looked everywhere on the Endpoint Protection menus.



  • 7.  RE: IPS DoS when adding remote printer

    Posted Dec 18, 2010 11:29 PM

    Open your IPS policy and see screenshot below on how to add: