Splunk Search

Using Splunk to analyze firewalls, how can I detect attackers who are doing IP spoofing attacks?

btb2018
Engager

How can I detect attackers using IP spoofing in Splunk?

I want to be able to detect this in Checkpoint and Juniper firewalls.

I presume a standard search operation would work, but how is anti-spoofing reported?

Thanks

0 Karma
1 Solution

mydog8it
Builder

I do not have Checkpoint experience, but here is info from Checkpoint's website:
Logs shows that traffic is dropped with "message_info: Address spoofing" in the "Information" field.
These logs appear for inbound packets on the external interface of Security Gateway, although these packets were received from the network that belongs to the same external interface.

Search for the action in the messages that match above

View solution in original post

mydog8it
Builder

I do not have Checkpoint experience, but here is info from Checkpoint's website:
Logs shows that traffic is dropped with "message_info: Address spoofing" in the "Information" field.
These logs appear for inbound packets on the external interface of Security Gateway, although these packets were received from the network that belongs to the same external interface.

Search for the action in the messages that match above

btb2018
Engager

The aim here is to use Splunk to analyse firewalls.
The requirement is to use Splunk to see if any IP spoofing attacks have occurred.
Using index=checkpoint-opsec I am able to, for example, analyse the logs but which value in Checkpoint\ Juniper represents a spoofing attack or drop due to anti-spoofing on the firewall?

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...