Legitimate traffic

Forescout provides a set of options for handling legitimate traffic in your network.

About handling legitimate activity from malicious sources

You can define rules for allowing specific kinds of probes at your network. This type of activity is referred to as legitimate traffic activity. Once these rules are defined, endpoints that perform Legitimate Traffic are ignored. Specifically, they are not counted in the probe count by Forescout eyeControl when attempting to probe defined services or host.

By default, the Legitimate Traffic rule is set to ignore NetBIOS and port probes by any source to any real host on any service. This allows eyeControl to ignore legitimate network activity and handle activity on virtual endpoints that it creates.

You should keep the default settings, and then use the Legitimate Traffic tools to add other Legitimate Traffic rules, as required. For example, if you are performing vulnerability assessments from specific addresses on specific ports, or for a printer that is required to scan the network to find a server to connect to, or any other business requirement that compels you to grant full access to specific addresses.

Centralized Management

Legitimate Traffic rules can be centrally managed via the Enterprise Manager for all connected Appliances. This means the rules defined in the Enterprise Manager are applied to all Appliances. Centralized management ensures consistency in Legitimate Traffic probe definitions across your enterprise. This eliminates the process of redefining the rules at each Appliance, making it easier to conclude deployment.

When registering an Appliance to the Enterprise Manager, all legitimate traffic rules configured on that Appliance are replaced by the rules on the Enterprise Manager.

Centralized Management

Legitimate Traffic rules can be centrally managed via the Enterprise Manager for all connected Appliances. This means the rules defined in the Enterprise Manager are applied to all Appliances. Centralized management ensures consistency in Legitimate Traffic probe definitions across your enterprise. This eliminates the process of redefining the rules at each Appliance, making it easier to conclude deployment.

When registering an Appliance to the Enterprise Manager, all legitimate traffic rules configured on that Appliance are replaced by the rules on the Enterprise Manager.

Activity at Other Services

If a legitimate source probes the legitimate endpoints and ports assigned to it, and does not probe any other ports or endpoints, that source is not marked as a probing source, and thus is not a candidate for monitoring and blocking. If the same source also probes at least three endpoints or ports not marked as legitimate within the defined time period, a mark is distributed to the source. If the source uses the mark, it is considered an infected source and as such is a candidate for monitoring and blocking.

Note: The default settings require that the source perform three probe events within a day in order for the system to mark the source as a probing source. See Customize Scan Recognition Criteria for details about changing the probe count criteria.

After a source is detected as offensive, its attempts to access the legitimate endpoints and ports assigned to it are blocked and monitored.

Centralized Management

Legitimate Traffic rules can be centrally managed via the Enterprise Manager for all connected Appliances. This means the rules defined in the Enterprise Manager are applied to all Appliances. Centralized management ensures consistency in Legitimate Traffic probe definitions across your enterprise. This eliminates the process of redefining the rules at each Appliance, making it easier to conclude deployment.

When registering an Appliance to the Enterprise Manager, all legitimate traffic rules configured on that Appliance are replaced by the rules on the Enterprise Manager.

View legitimate traffic

Legitimate Traffic is defined and managed from the Legitimate Traffic dialog box. From the dialog box, you can add, edit, and remove rules, as well as to filter information about the rules that you have already defined. A feature is also available to import and export Legitimate Traffic rules.

To view the legitimate traffic list, select Tools > Options, and then select Threat Protection > Legitimate Scan.

images/image605.png

The following information is available:

Enabled
Indicates that the rule is enabled.
Rule
Several types of rules can be created. For example, custom design rules, known scanning application rules or removed server rules. This column details the rule type created.
Last Change
The date the rule was most recently modified.
Source
The source addresses to which the rule is applied.
Target
The destination addresses to which the rule is applied.
Type
The probe types included in the rule. For example, to allow HTTP probes only. The following options are available: Finger, HTTP, Login, NetBIOS, SNMP, and Port.
Port
The service to which the rule applies.
Real Hosts Only
Indicates that the rule was applied to real endpoints only.
Comment
Displays one of several methods used for defining Legitimate Traffic rules. The methods are detailed later in this section.