Splunk Search

Using Splunk to analyze firewalls, how can I detect attackers who are doing IP spoofing attacks?

btb2018
Engager

How can I detect attackers using IP spoofing in Splunk?

I want to be able to detect this in Checkpoint and Juniper firewalls.

I presume a standard search operation would work, but how is anti-spoofing reported?

Thanks

0 Karma
1 Solution

mydog8it
Builder

I do not have Checkpoint experience, but here is info from Checkpoint's website:
Logs shows that traffic is dropped with "message_info: Address spoofing" in the "Information" field.
These logs appear for inbound packets on the external interface of Security Gateway, although these packets were received from the network that belongs to the same external interface.

Search for the action in the messages that match above

View solution in original post

mydog8it
Builder

I do not have Checkpoint experience, but here is info from Checkpoint's website:
Logs shows that traffic is dropped with "message_info: Address spoofing" in the "Information" field.
These logs appear for inbound packets on the external interface of Security Gateway, although these packets were received from the network that belongs to the same external interface.

Search for the action in the messages that match above

btb2018
Engager

The aim here is to use Splunk to analyse firewalls.
The requirement is to use Splunk to see if any IP spoofing attacks have occurred.
Using index=checkpoint-opsec I am able to, for example, analyse the logs but which value in Checkpoint\ Juniper represents a spoofing attack or drop due to anti-spoofing on the firewall?

0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...