Skip to main content
Cajuntank
Contributor III
September 8, 2023
Solved

New threats and Intrusion Prevention

  • September 8, 2023
  • 1 reply
  • 5676 views

Just wondering, as I did not want to just assume things, but had 2 questions as it relates to new threats/vulnerabilities and using IPS to mitigate against.

1. If an IPS profile is created via filter, will any new signature, updated from the subscription, that matches to said filter, automatically also apply? eg... if I have a filter based on macOS, is a new signature that is macOS applicable, dynamically applied as well since it is a dynamic filter (again, sounds logical, but don't want to assume)?

2. What is the normal turn-around for new vulnerabilities to then be turned around into IPS signatures from FortiGuard for the database to be updated? eg... Apple has some new vulnerabilities (CVE-2023-41064, CVE-2023-41061) that was disclosed yesterday (but CVE was created back on the 22nd of last month). FortiGuard has nothing about those on their website as of yet.

Best answer by FortiNet_Newb

According to the Administrative Guide (for FortiOS 7.2.5 anyway), your assumption is correct.  If you have an active IPS license, the new signatures will be automatically applied to any existing filters.  Here is the excerpt:

 

"The FortiGuard Service periodically adds new predefined signatures to counter new threats. New predefined signatures are automatically included in IPS sensors that are configured to use filters when the new signatures match existing filter specifications. For example, if you have an IPS sensor with a filter that includes all signatures for the Windows operating system, your filter will automatically incorporate new Windows signatures that the FortiGuard Service adds to the database."

1 reply

Raghu_Kumar
Staff
Staff
September 9, 2023

Hello @Cajuntank,

 

1. If you have active license for IPS, the signatures are actively updated if you have active connectivity to FortiGuard servers.

 

2.Once CVE is reported globally. It takes some time for PSIRT (Product Security Incident Response Team)  for an official release about the CVE.

For the detail of the respective CVE, kindly be informed that the relevant will be shared via our official PSIRT announcement in short future. Please monitor this page: https://www.fortiguard.com/psirt as the respective information would be published in the respective page.
unknown1020
Explorer III
September 9, 2023

Hello, is there a way that the new vulnerabilities published on this page can reach me by email? as notification

Raghu_Kumar
Staff
Staff
September 9, 2023

To get PSIRT notifications:

  1. Log into support.fortinet.com

  2. In the top right corner, click on your name and select My Account

  3. On the Account page, click on My Account (IAM version)

  4. On the left side, click on Account Preferences

  5. On the top right corner of the Account Preferences page click Edit

  6. At the bottom, under PSIRT Contact, enter the email addresses you’d like to have notified of any future PSIRTs released (comma delimited)

  7. Click Update in the top right corner, where you clicked Edit in step 5.

This should get you all email notifications on future PSIRTS