Splunk Search

Using Splunk to analyze firewalls, how can I detect attackers who are doing IP spoofing attacks?

btb2018
Engager

How can I detect attackers using IP spoofing in Splunk?

I want to be able to detect this in Checkpoint and Juniper firewalls.

I presume a standard search operation would work, but how is anti-spoofing reported?

Thanks

0 Karma
1 Solution

mydog8it
Builder

I do not have Checkpoint experience, but here is info from Checkpoint's website:
Logs shows that traffic is dropped with "message_info: Address spoofing" in the "Information" field.
These logs appear for inbound packets on the external interface of Security Gateway, although these packets were received from the network that belongs to the same external interface.

Search for the action in the messages that match above

View solution in original post

mydog8it
Builder

I do not have Checkpoint experience, but here is info from Checkpoint's website:
Logs shows that traffic is dropped with "message_info: Address spoofing" in the "Information" field.
These logs appear for inbound packets on the external interface of Security Gateway, although these packets were received from the network that belongs to the same external interface.

Search for the action in the messages that match above

btb2018
Engager

The aim here is to use Splunk to analyse firewalls.
The requirement is to use Splunk to see if any IP spoofing attacks have occurred.
Using index=checkpoint-opsec I am able to, for example, analyse the logs but which value in Checkpoint\ Juniper represents a spoofing attack or drop due to anti-spoofing on the firewall?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...