Skip to main content
madunix
New Member
December 15, 2015
Question

Zeus

  • December 15, 2015
  • 3 replies
  • 5937 views

How yo block Zeus?

    3 replies

    gschmitt
    New Member
    December 15, 2015

    AV:

    Go to Security Profiles > AntiVirus and change the radiobutton below â˜‘ Detect Connections to Botnet C&C Servers from Monitor to Block, hit Apply

     

    Application Control:

    Go to Security Profiles > Application Control, click the Botnet Category and select Block, hit Apply

     

    Make sure that the Security Profile is active on your internal to wan policy. Either one should work.

    ede_pfau
    SuperUser
    SuperUser
    December 15, 2015

    Either one should work.
    Actually, the two work on different aspects of botnets.

     

    The botnet C&C IP address blacklist is distributed and updated via the AV engine. This is a simple but effective address filter with near to no impact on CPU.

    The AppCtrl signature checks for botnet activity which is not necessarily traffic to the C&C servers.

    As such, CPU or CP load is a bit higher.

     

    Both methods should be used at any installation as they complement each other.

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!