Forum Discussion

Rchattop_307189's avatar
Rchattop_307189
Icon for Nimbostratus rankNimbostratus
Jan 22, 2017

Best practice to put security signatures in blocking mode

What is the best practice to put security signatures in blocking mode. Should we put security signatures in blocking mode before putting it in production or will put it in detection mode and after analyzing the traffic we will put them in blocking mode one by one? If we will follow second method is there any possibilities to block legitimate traffic suddenly when we will change any signature in blocking mode. Do we have any best practice document on this.

 

4 Replies

  • im afraid there won't be any best practice because it just differs per requirements of the user.

     

    do you want to be more safe and risk (some) false positives, put them into blocking right away.

     

    do you want to be a little less safe put them info staging and see if they are hit, investigate and after staging enable them.

     

  • is it possible to put few of the known malicious signatures in blocking mode initially and rest of the signatures in detection mode.

     

  • Yes. It's possible. We need to enable signature staging and enforce each signature individually which will go to blocking mode.