Description

This article discusses the different signatures to be used in an IDP policy to mitigate the SMB vulnerabilities that WannaCry ransomware exploits.

For more information on the vulnerability, please refer to the Rapid Response blog.

This article is applicable to all devices that support the IDP feature, including SRX, SA-IDP and ISG-IDP devices.

Solution

The following signatures are recommended to be used on IDP devices to mitigate the attack:

SMB:ERROR:MAL-MSG 
SMB:CVE-2017-0146-OOB 
SMB:CVE-2017-0147-ID 
SMB:SMBV1-REQ 
SMB:CVE-2017-0148-RCE 
SMB:CVE-2017-0145-RCE 

Please refer to the Juniper Signatures page for more details on these signatures.