This article discusses the different signatures to be used in an IDP policy to mitigate the SMB vulnerabilities that WannaCry ransomware exploits. For more information on the vulnerability, please refer to the Rapid Response blog. This article is applicable to all devices that support the IDP feature, including SRX, SA-IDP and ISG-IDP devices.
The following signatures are recommended to be used on IDP devices to mitigate the attack:
SMB:ERROR:MAL-MSG SMB:CVE-2017-0146-OOB SMB:CVE-2017-0147-ID SMB:SMBV1-REQ SMB:CVE-2017-0148-RCE SMB:CVE-2017-0145-RCE
Please refer to the Juniper Signatures page for more details on these signatures.