Security Profiles: AV, Anti-Spyware, Vulnerability & IPS
Palo Alto NGFW — PCNSE track EVE-NG — PAN-OS VM (GUI + CLI)
مقصدObjectiveObjective
اے وی، اینٹی اسپائی ویئر اور ولنریبیلیٹی پروفائلز بنانا، انہیں سیکیورٹی رول سے اٹیچ کرنا، اور آئی پی ایس ایکشنز سمجھنا۔AV, anti-spyware aur vulnerability profiles banana, unhein security rule se attach karna, aur IPS actions samajhna.Create AV, anti-spyware, and vulnerability profiles, attach them to a security rule, and understand IPS actions.
آسان مثالSimple AnalogySimple Analogy
سیکیورٹی پروفائلز سیٹ بیلٹس اور ایئر بیگز کی طرح ہیں: سیکیورٹی رول کار کو روڈ پر آنے کا فیصلہ ہے، پروفائلز وہ سیفٹی گیئر ہیں جو ہر سفر میں ساتھ ہوتا ہے۔Security profiles seatbelts aur airbags ki tarah hain: security rule car ko road par aane ka faisla hai, profiles woh safety gear hain jo har safar mein saath hota hai.Security profiles are like seatbelts and airbags: the security rule is the decision to let the car on the road, the profiles are the safety gear that rides along on every trip.
سیٹ اپLab SetupLab Setup
پالو-03 کا بلڈ ٹرسٹ ٹو ان ٹرسٹ رول کے ساتھ کنٹینیو کریں۔ آپ اسے پروفائل گروپ اٹیچ کریں گے اور ٹیسٹ ٹریفک جنریٹ کریں گے (براؤز، ای آئی سی اے آر ٹیسٹ فائل ڈاؤن لوڈ)۔palo-03 ka build Trust-to-Untrust rule ke saath continue karein. Aap ise profile group attach karenge aur test traffic generate karenge (browse, EICAR test file download).Continue the palo-03 build with the Trust-to-Untrust rule. You will attach a profile group to it and generate test traffic (browse, download the EICAR test file).
اقداماتStepsSteps
Step 1
اینٹی وائرس پروفائل بنائیں جو ڈیٹیکٹڈ میلویئر کو بلاک کرے۔ لیب میں بلاک ٹھیک ہے؛ پروڈکشن میں کئی ٹیمز الرٹ سے اسٹارٹ کرتی ہیں۔Antivirus profile banayein jo detected malware ko block kare. Lab mein block theek hai; production mein kai teams alert se start karti hain.Create an antivirus profile that blocks detected malware. In a lab, block is fine; in production many teams start with alert.
set profiles virus Strict-AV decoder http action block commit
🖱️ آبجیکٹس > سیکیورٹی پروفائلز > اینٹی وائرس: ’اسٹرکٹ اے وی‘ ایڈ کریں، سب ڈیکوڈرز بلاک پر سیٹ کریں۔Objects > Security Profiles > Antivirus: 'Strict-AV' add karein, sab decoders block par set karein.Objects > Security Profiles > Antivirus: Add 'Strict-AV', set all decoders to block.
Step 2
اینٹی اسپائی ویئر پروفائل بنائیں — یہ کمانڈ اینڈ کنٹرول کال بیکس پکڑتا ہے، کمپرومائزڈ ہوسٹ کی کلاسک نشانی۔Anti-spyware profile banayein — ye command-and-control callbacks pakarta hai, compromised host ki classic nishani.Create an anti-spyware profile — this catches command-and-control callbacks, the classic sign of a compromised host.
set profiles spyware Strict-AS rules all action block commit
🖱️ آبجیکٹس > سیکیورٹی پروفائلز > اینٹی اسپائی ویئر: ’اسٹرکٹ اے ایس‘ ایڈ کریں، سب سیویرٹی رولز پر ایکشن بلاک۔Objects > Security Profiles > Anti-Spyware: 'Strict-AS' add karein, sab severity rules par action block.Objects > Security Profiles > Anti-Spyware: Add 'Strict-AS', action block for all severity rules.
Step 3
ولنریبیلیٹی (آئی پی ایس) پروفائل بنائیں۔ ری سیٹ بوتھ ایکسپلائٹ سیشن کے دونوں سائیڈز مار دیتا ہے — ایکٹیو اٹیکس کے لیے ڈراپ سے اسٹرانگ۔Vulnerability (IPS) profile banayein. reset-both exploit session ke dono sides maar deta hai — active attacks ke liye drop se strong.Create a vulnerability (IPS) profile. reset-both kills both sides of an exploit session — stronger than drop for active attacks.
set profiles vulnerability Strict-VP rules all action reset-both commit
🖱️ آبجیکٹس > سیکیورٹی پروفائلز > ولنریبیلیٹی پروٹیکشن: ’اسٹرکٹ وی پی‘ ایڈ کریں، کریٹیکل/ہائی پر ایکشن ری سیٹ بوتھ۔Objects > Security Profiles > Vulnerability Protection: 'Strict-VP' add karein, critical/high par action reset-both.Objects > Security Profiles > Vulnerability Protection: Add 'Strict-VP', action reset-both for critical/high.
Step 4
پروفائلز کو گروپ میں بنڈل کریں اور آؤٹ باؤنڈ رول سے اٹیچ کریں۔ ہر رول پر ایک گروپ — رول بیس ریڈیبل رہتا ہے۔Profiles ko group mein bundle karein aur outbound rule se attach karein. Har rule par ek group — rulebase readable rehta hai.Bundle the profiles into a group and attach it to the outbound rule. One group per rule keeps the rulebase readable.
set profile-group Branch-Strict virus Strict-AV spyware Strict-AS vulnerability Strict-VP set rulebase security rules Trust-to-Untrust profile-setting group Branch-Strict commit
🖱️ آبجیکٹس > سیکیورٹی پروفائلز > پروفائل گروپس: تینوں کو بنڈل کر کے ’برانچ اسٹرکٹ‘ ایڈ کریں۔ پالیسیز > سیکیورٹی: ٹرسٹ ٹو ان ٹرسٹ ایڈٹ کریں، ایکشنز ٹیب: پروفائل سیٹنگ = برانچ اسٹرکٹ۔Objects > Security Profiles > Profile Groups: teeno ko bundle karke 'Branch-Strict' add karein. Policies > Security: Trust-to-Untrust edit karein, Actions tab: Profile Setting = Branch-Strict.Objects > Security Profiles > Profile Groups: Add 'Branch-Strict' bundling the three. Policies > Security: edit Trust-to-Untrust, Actions tab: Profile Setting = Branch-Strict.
Step 5
ہارملس ای آئی سی اے آر ٹیسٹ فائل سے ٹیسٹ کریں — تھریٹ لاگ میں آپ کی رول سے جڑا وائرس بلاک نظر آنا چاہیے۔ پروفائل کام کرنے کا سیف ثبوت۔Harmless EICAR test file se test karein — threat log mein aapki rule se jura virus block nazar aana chahiye. Profile kaam karne ka safe saboot.Test with the harmless EICAR test file — the threat log should show a virus block tied to your rule. Safe proof that the profile works.
show threat id 40000
🖱️ مانیٹر > لاگز > تھریٹ: لین ہوسٹ سے ای آئی سی اے آر ٹیسٹ فائل ڈاؤن لوڈ کریں اور بلاک انٹری آتے دیکھیں۔Monitor > Logs > Threat: LAN host se EICAR test file download karein aur block entry aate dekhein.Monitor > Logs > Threat: download the EICAR test file from a LAN host and watch the block entry appear.
تصدیقVerifyVerify
ای آئی سی اے آر ڈاؤن لوڈ بلاک ہو گیا اور آپ کی رول کے نام سے وائرس تھریٹ لاگ ہوا؛ نارمل براؤزنگ اب بھی کام کرتی ہے۔EICAR download block ho gaya aur aapki rule ke naam se virus threat log hua; normal browsing ab bhi kaam karti hai.The EICAR download is blocked and logged as a virus threat under your rule name; normal browsing still works.
show session all filter application web-browsing
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ ای آئی سی اے آر فائل بغیر کسی تھریٹ لاگ انٹری کے ڈاؤن لوڈ ہو گئی۔EICAR file bina kisi threat log entry ke download ho gayi.The EICAR file downloads without any threat log entry.
✅ پروفائل گروپ میچنگ رول سے اٹیچ نہیں، یا ٹریفک نے دوسری رول میچ کی۔ رول پر پروفائل سیٹنگ کنفرم کریں اور دیکھیں سیشن نے کون سی رول ہٹ کی۔Profile group matching rule se attach nahi, ya traffic ne doosri rule match ki. Rule par profile-setting confirm karein aur dekhein session ne kaun si rule hit ki.The profile group is not attached to the matching rule, or traffic matched a different rule. Confirm profile-setting on the rule and check which rule the session hit.
⚠️ ولنریبیلیٹی پروفائل ایک لیجیٹیمیٹ بزنس ایپ کو ری سیٹ کر رہا ہے۔Vulnerability profile ek legitimate business app ko reset kar raha hai.Legitimate business app gets reset by the vulnerability profile.
✅ تھریٹ لاگ میں سگنیچر ڈھونڈیں اور اس سگنیچر کے لیے ایکسیپشن بنائیں (یا اس رول کو الرٹ پر لے آئیں)۔ ایک ایپ کے لیے پورا پروفائل ڈس ایبل کبھی نہ کریں۔Threat log mein signature dhoondhein aur us signature ke liye exception banayein (ya us rule ko alert par le aayein). Ek app ke liye poora profile disable kabhi na karein.Find the signature in the threat log and create an exception for that signature (or lower that rule to alert). Never disable the whole profile for one app.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ سیکیورٹی رول اور سیکیورٹی پروفائل میں کیا فرق ہے؟Security rule aur security profile mein kya farq hai?What is the difference between a security rule and a security profile?
پروفائلز خود الاؤ یا بلاک نہیں کرتے — یہ سیکیورٹی رولز سے اٹیچ ہوتے ہیں اور الاؤڈ ٹریفک کو اسکین کرتے ہیں: میلویئر کے لیے اینٹی وائرس، سی ٹو کے لیے اینٹی اسپائی ویئر، ایکسپلائٹس کے لیے ولنریبیلیٹی پروٹیکشن۔Profiles khud allow ya block nahi karte — ye security rules se attach hote hain aur allowed traffic ko scan karte hain: malware ke liye antivirus, C2 ke liye anti-spyware, exploits ke liye vulnerability protection.Profiles do not allow or block by themselves — they attach to security rules and scan the allowed traffic: antivirus for malware, anti-spyware for C2, vulnerability protection for exploits.
❓ IPS signature session پر کیا actions لے سکتا ہے؟IPS signature session par kya actions le sakta hai?What actions can an IPS signature take on a session?
آئی پی ایس سگنیچرز نون اٹیک پیٹرنز سے میچ کرتے ہیں اور سیشن کو الاؤ، الرٹ، ڈراپ یا ری سیٹ کر سکتے ہیں۔ ری سیٹ کنکشن مار دیتا ہے؛ ڈراپ پیکٹس کو چپ چاپ گرا دیتا ہے۔IPS signatures known attack patterns se match karte hain aur session ko allow, alert, drop ya reset kar sakte hain. Reset connection maar deta hai; drop packets ko chup chaap gira deta hai.IPS signatures match known attack patterns and can allow, alert, drop, or reset the session. Reset kills the connection; drop silently discards packets.