Handle service attacks

Forescout eyeControl identifies a service attack when a certain service-probing criterion is met. This criterion is automatically calculated and is based on the size of your network. The sensitivity threshold can be adjusted to identify the attack after fewer or more service-probing events occur.

Forescout eyeControl handles service attacks by monitoring or blocking all endpoints at attacked services in the network. This differs from the standard response to individual endpoints that attempt to scan or attack any port in the network.

By using the monitor option, all traffic going to attacked services is recorded for a defined time period and not just the traffic of the probing endpoint. After the time period has expired, eyeControl stops recording traffic in the services. If the service attack criterion is met again, endpoints are monitored again for the time set.

By using the block option, you are blocking all traffic to the attacked services for a defined time period and not just the traffic of the infected endpoint. After the time period has expired, traffic is allowed. If the service attack criterion is met again, endpoints are blocked again for the time period set. Use the block option to prevent worm attacks from reaching the service at other endpoints in your network.

By default, both UDP and TCP are monitored for 12 hours. TCP ports 68, 80, 113, 443 and 1080 are ignored. UDP ports 68, 113, 1080 and 33434-33524 are ignored.

You can disable this feature for either service. When disabled, traffic going to the selected service is neither blocked nor monitored. The response is disabled until you enable it again.

You can also remove the current monitor or block state endpoints in the service.

In addition, users listed in the Email configuration dialog box are sent an email notification alert whenever a service attack occurs.

Note: Blocking services should be carried out carefully. When the service is blocked, no communication to the service is allowed for any endpoint, even if the endpoint is not malicious. Therefore, it is recommended to only monitor services.

UDP blocking prerequisites

To block endpoints at UDP services, you must configure your system to block with Forescout eyeControl and a firewall. Not all firewall products support service blocks. If your firewall does not support service blocks, you receive an error message.

How do I know when a service has been attacked?

The service attack indicator images/image579.png on your status bar flickers when a new service is attacked.

You can view service attacks from the Threats view, the Service Attack folder.

In addition, email alerts are sent when a service attack occurs, provided that you do not disable this option. The following tools are also available: