Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tamiltk
New Contributor II

Covert Malware communication

Need evidence where FortiGate IPS detecting the Covert Malware communication detection.

FortiGate

3 REPLIES 3
AnthonyH
Staff
Staff

Hello Tamiltk,

 

Could you further explain what is occurring? Are there any logs under Log & report -> Security Events -> IPS, about traffic being bypass/blocked?

Technical Support Engineer,
Anthony.
Tamiltk
New Contributor II

There wasn't any incident triggered on this subject. I just need an artifact that Fortigate IPS does support Covert Malware communication detection

kaman
Staff
Staff

Hi Tamiltk,

From the IPS signatures' point of view, we have signatures to detect botnet communication, remote access tools, reverse shells, etc. To detect communications over covert channels, make sure an IPS sensor with all signatures is enabled with the default action, as it should detect and/or block these communications.

Please enable deep inspection, as most of the traffic is in the HTTPS protocol and needs to be decrypted.

If you have found a solution, please like and accept it to make it easily accessible to others.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors