You are here
SEC0172 - ASA FirePower Malware Detection (Part 2)
Difficulty Level:
Lab Document:
<Please login to see the content>
Category:
Security
The video demonstrates Cisco ASA FirePower ability to perform Malware file detection and blocking. We will look at how a file is determined to contain malware, specifically executable files. We will attempt to submit a file with unknown disposition for further cloud analysis, explain the meaning of threat score, and review file analysis report. Finally, we will introduce you to Clean and Detection list and how they can be used to overwrite the default malware detection behavior.
Part 2 of this video goes through Clean and Detection list, threat score, and possible integration with Endpoint FireAMP
Topic:
- File Malware Detection and Blocking
- File Malware Dynamic and Spero Analysis
- File Trajectory
- File Capture and SHA256 Digest
- File Clean and Detection List
- Threat Score and Cloud Analysis Report
- Endpoint FireAMP Integration
6 comments
Malware Warning
When malware is detected can the system display a webpage indicating the reason why the download stopped?
Malware Warning
To our knowledge, it is not possible. FP will silently drop traffic and generate log entry.
Block Malware
Hello, What happens when we choosed Block malware with dynamic analysis option and system detects file with unknown disposition? Will it send it to cloud and wait until answer come or pass first packet and send copy to cloud for further detection?
Block Malware
Firepower never blocks the first file with unknow disposition. Only when the dynamic analysis results comes back as malware, the subsequent file will be blocked.
Firepower, how long store
Firepower, how long store Malware & unknown files ? Are these files auto deletes ? I see its consuming disk space.
Firepower, how long store
FMC store files until allocated disk space is filled and will start deleting the oldest file. You can also install malware storage pack to increase capacity.