Splunk Search

Using Splunk to analyze firewalls, how can I detect attackers who are doing IP spoofing attacks?

btb2018
Engager

How can I detect attackers using IP spoofing in Splunk?

I want to be able to detect this in Checkpoint and Juniper firewalls.

I presume a standard search operation would work, but how is anti-spoofing reported?

Thanks

0 Karma
1 Solution

mydog8it
Builder

I do not have Checkpoint experience, but here is info from Checkpoint's website:
Logs shows that traffic is dropped with "message_info: Address spoofing" in the "Information" field.
These logs appear for inbound packets on the external interface of Security Gateway, although these packets were received from the network that belongs to the same external interface.

Search for the action in the messages that match above

View solution in original post

mydog8it
Builder

I do not have Checkpoint experience, but here is info from Checkpoint's website:
Logs shows that traffic is dropped with "message_info: Address spoofing" in the "Information" field.
These logs appear for inbound packets on the external interface of Security Gateway, although these packets were received from the network that belongs to the same external interface.

Search for the action in the messages that match above

btb2018
Engager

The aim here is to use Splunk to analyse firewalls.
The requirement is to use Splunk to see if any IP spoofing attacks have occurred.
Using index=checkpoint-opsec I am able to, for example, analyse the logs but which value in Checkpoint\ Juniper represents a spoofing attack or drop due to anti-spoofing on the firewall?

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...