Security Compliance
Using the Threat Intelligence feed in SEM
This article details how to use the Threat Intelligence feed in SEM.
First published date
Last published date
Overview
This article details how to use the Threat Intelligence feed in Security Event Manager (formerly Log & Event Manager), and what is needed to allow updating threat feeds.
Threat Feeds help monitor DDoS attacks, Malware, Botnets, Spam and more. This helps to detect or pinpoint potential security issues like Phishing attempts, Malware infections, and external attacks from bad hosts.
Product section
Resolution
Proxy Server
Currently, SEM cannot be configured to use a proxy server, so it will need internet access through the firewall to reach the Threat Feeds website on port 443. Threat Feeds use a different port and website, as compared to the automated Connector Updates.
Internet access needed for threat feeds
Threat feeds:
https://rules.emergingthreats.net (Emerging Threats, available at rules.emergingthreats.net, obtained on December 18, 2018). Possible IP's: 96.43.137.99 & 204.12.217.19 & 54.231.64.20 & 69.20.68.177.
Connector updates:
Connector updates uses port 80 to http://downloads.solarwinds.com. Possible IP's: 23.212.53.182 & 23.212.53.190 & 64.48.225.51 & 64.48.225.99.
Verify your Threat Intelligence feed is enabled and updating (OLD Flash Console)
- Go to Manage > Appliance > Settings.
- Verify the feed is enabled as shown below.
Note: Every morning at 3:14 AM, your SEM updates its Threat Intelligence Feed list. You will find a daily event under Monitor > SEM Internal Events confirming if the update is successful or failed.
Verify the feed is enabled in the HTML5 SEM Events Console
- In the SEM Events Console, click the settings button.
- On the Settings page, click the Threat Intelligence tab.
- Toggle the button to allow SEM to enable the Threat Intelligence feed.
Note: Only administrators have permissions to enable or disable the Threat Intelligence feed. Disabling and re-enabling the Threat Intelligence feed forces a Threat Intelligence update and creates an InternalAudit event. Restarting SEM also forces the Threat Intelligence feed to update.
The Threat Intelligence feed has a specific field: isThreat. This field is only displayed on network-related events or event groups, such as events with Traffic in its name. If this field is marked as True, one of the source or destination fields hit an IP address or domain that is blacklisted.
There are three built-in rule templates you can clone and use to be alerted for any suspicious activity. Enable any of these as appropriate for your environment. They should need no customization besides specifying a user to receive the email alert.
With versions 6.7 and later, you can access the rule templates in the SEM Events Console Rules tab.