This article discusses the different options available to Juniper customers who have deployed Juniper firewall products in their networks to protect the network from the WannaCry Ransomware exploits. Please refer to the Rapid Response blog for an understanding of the attack mechanics used by Wannacry. This will help you understand the protection options discussed in this article. This article is applicable to ScreenOS Firewalls (SSG/ISG), Hardware SRX firewalls and virtual SRX Deployments.
UTM Defense provided by ScreenOS Firewalls:
ScreenOS UTM is comprised of four basic components - Antivirus (AV), Deep Inspection (DI), URL Filtering (UF) and Antispam (AS). Out of these, AV and DI can help prevent the WannaCry Infection as follows:
AntiVirus: The Antivirus Solution can scan HTTP, FTP and email traffic. It can detect and stop the initial download of the Trojan (referred to as 'Portable Executable' in the blog). The virus definitions are a part of pattern updates rolled out on May-15, 2017 and later. Please ensure you have the latest Virus definitions and AV enabled on the right policies.
Deep Inspection: DI is capable of scanning SMB transactions. When deployed right, it can prevent the lateral propagation of the malware within the network. The following signatures can aid in this regard. They were rolled out as a part of Attack database Version: 2894. SMB:ERROR:MAL-MSG SMBCVE-2017-0146-OOB SMB:CVE-2017-0147-ID SMB:CVE-2017-0148-RCE SMB:CVE-2017-0145-RCE
One additional signature was rolled out as a part of Attack database Version: 2895 and is represented by:
SMB:SMBV1-REQ
Please note this signature is designed to stop all SMB-V1 requests. In case you have genuine SMB transactions in your network, still on Version-1, deploying this signature can impact production traffic.
Please refer to the Juniper Signatures page for more details on these signatures.
IDP Protection By ISG Firewalls:
Both ISG-1000 and ISG-2000 devices support IDP by utilising dedicated IDP blades that can be installed on the chassis. The same signatures mentioned above are a part of the IDP signature database as well. Please note that the same precaution for applying 'SMB:SMBV1-REQ' should be considered here as well.
Antivirus Solutions by SRX Firewalls:
SRX Firewalls support 3 different flavors of AV:
Virus definitions for all 3 flavours contain signatures to detect the initial dowload of the Trojan. Please ensure you have enabled AV on the right policies.
IDP Protection By SRX Firewalls:
Same signatures mentioned above, to scan and analyse SMB traffic. Please note that the same precaution for applying 'SMB:SMBV1-REQ' should be considered here as well.