Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added remediations for ndpi alerts #8627

Merged
merged 1 commit into from
Aug 16, 2024
Merged

Added remediations for ndpi alerts #8627

merged 1 commit into from
Aug 16, 2024

Conversation

DGabri
Copy link
Contributor

@DGabri DGabri commented Aug 16, 2024

Please sign (check) the below before submitting the Pull Request:

Link to the related issue:

Describe changes:
Added remediations for ndpi alerts

@DGabri DGabri requested a review from MatteoBiscosi August 16, 2024 09:10
@MatteoBiscosi MatteoBiscosi merged commit 15ba12f into ntop:dev Aug 16, 2024
5 checks passed
@lucaderi
Copy link
Member

@DGabri @MatteoBiscosi This work is broken, not glued with the documentation, untested. Not a great job by both of you.

@lucaderi
Copy link
Member

Example
MALICIOUS JA3

  • Description: This risk indicates a detection of a malicious Java Application (Java 3) in the monitored network.
  • Possible attacks: The presence of this application can signal various threats such as code injection, data theft, or unauthorized access due to its outdated nature and known vulnerabilities. It may also serve
    as a vector for malware distribution.
  • Remediation: To secure the network when this risk is detected:
    1. Isolate any devices running Java 3 applications immediately to prevent further potential damage or spread of threats.
    2. Apply updates for the Java Application as soon as possible to patch known vulnerabilities and improve security.
    3. Implement strict access controls and whitelist trusted applications on the network.
    4. Monitor network traffic closely for any unusual activity related to Java 3 and take appropriate action if necessary.
    5. Regularly scan devices for malware and ensure that antivirus software is up-to-date and functioning properly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants