IoC Feeds

Introduction

An Indicator of Compromise (IoC) identifies malicious activity in a cyber environment, and consists of:

  • Observables

  • Behavioral patterns

  • Contextual intelligence

Together, these elements turn raw data into actionable threat intelligence.

An Observable is an event or a stateful property that can be observed in an operational cyber environment, such as:

  • An IP address

  • A file signature

  • A URL

  • An email address.

Observables are raw data points. They become actionable threat indicators with added behavior descriptions and context.

How Threat Indicators Describe Attacks

Threat indicators demonstrate attacks through:

Indicator Sources

Indicators are derived from multiple sources, including:

  • Threat intelligence providers

  • Internal analysis

  • Government organizations

  • Trusted partners.

IoC Feeds Feature

The IoC Feeds feature fetches feeds from a third-party server directly to the Security GatewayClosed A dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources.. The Security Gateway enforces the feeds through the Anti-Bot, Anti-Virus and IPS engines, in addition to the feeds included in the Check Point packages and ThreatCloud feeds. The IoC Feeds feature manages and monitors indicators with minimum operational overhead.

To configure an IoC Feed for Centrally Managed Spark Firewall Appliances:

  1. In the SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. main view, go to Security Policies > Threat Prevention > Custom Policy > Custom Policy Tools > Indicators.

  2. Click New and select New IoC Feed.

    The New IoC Feed configuration window opens

  3. In the top field, enter a name for the feed.

  4. In the Action field, select the applicable action:

    • Prevent - Threat Prevention Software Blades block the detected observable.

    • Detect - Threat Prevention Software Blades logs and allows the detected observable to pass.

    • Inactive - Disables this feed.

  5. In the Feed URL field, enter the full URL that starts with http:// or https://.

  6. From the Format drop-down menu:

    1. select the applicable format (see sk132193 for more information on the feed settings):

      • Check Point format

      • Custom CSV

      These are the supported types of observables:

      • IP

      • IP range

      • Domain

      • URL

      • Hashes (MD5, SHA1, SHA256)

      • Email attributes (Subject, From, To, CC, Reply to).

      See sk132193 for more information on the feed's settings.

    2. Configure the applicable feed parsing settings.

  7. Click OK.

    The new feed appears on the Indicators page.

  8. The Security Gateway fetches the configured feeds every 30 minutes and enforces them immediately. To change the fetching interval:

    1. Go to the Manage & Settings view > Blades> Threat Prevention > Advanced Settings.

    2. From the left navigation tree, select External Feed.

    3. Configure the applicable interval.

    4. Click OK.

  9. Install the Threat Prevention Policy.

Limitations for Centrally Managed Spark Firewall Appliances

IoC Feeds do not support:

  • Snort and STIX formats

  • Test feed button

  • User authentication for a feed

  • Use of Gateway proxy for connection to the external feed

  • These commands in Expert mode: add, push, export, show_interval, set_interval, set_scanning_mode, yes, no_proxy, self_sign_certificate, format, delimeter, comment, feed_file_type, severity, confidence, performance_impact.

  • Fetching feeds from an HTTPS server with a self signed certificate.

  • Policy installation installs successfully even if a Security Gateway cannot fetch a feed. In this case, the Security Gateway generates a control log.