A signature shows up in output as Major Severity, but is not listed in the predefined attack group DNS - Major. This article explains how to check a signature and see its assigned attack group.
Check the signature with the command show security idp attack detail .
show security idp attack detail
DNS: ISC-BIND-CNAME-DNAME-DOS
root@SRX-550-1> show security idp attack detail DNS:ISC-BIND-CNAME-DNAME-DOS Display Name: DNS: ISC BIND Referral CNAME and DNAME Assertion Failure Denial of Service Severity: Major Category: DNS
It is showing under Category DNS and Severity: Major , however, it is not found in the predefined attack group DNS - Major
Category DNS
Severity: Major
root@SRX-550-1> file show /var/db/idpd/sets/idp1.set | find "DNS - Major" :"DNS - Major" ("DNS - Major" :type (group) :group ( :members ( : ("DNS:BIND-RRSIG-QUERY-DOS") : ("DNS:ISC-ASSERTION-DOS") : ("DNS:ISC-BIND-RPZ-DOS") : ("DNS:MUL-VEND-TXT-BOF") : ("DNS:NGINX-RESOLVER-DOS") : ("DNS:OVERFLOW:HOSTNAME-OF") : ("DNS:OVERFLOW:NOOP-RQUERY") : ("DNS:OVERFLOW:TRANSPOOF-3") : ("DNS:PDNS-AUTHSERV-DOS") : ("DNS:QUERY:BIND-IQUERY-BO") : ("DNS:QUERY:NULL-QUERY") : ("DNS:SYMANTEC-CACHE-POIS")> : ("DNS:WORDPRESS-SOAK-SOAK-MALWARE")
DNS:ISC-BIND-CNAME-DNAME-DOS
root@SRX-550-2# > file show /var/db/idpd/sets/idp1.set | find Misc_DNS - Major :Misc_DNS - Major ( Misc_DNS - Major :type (group) :group ( :members ( : (DNS:AUDIT:UNASSIGNED-OPCODE) : (DNS:AUDIT:Z-RESERVED-OPT) : (DNS:BIND-RRSIG-DOS-2) : (DNS:BIND9-ASSERT-DOS) : (DNS:DNAME-RESPONSE-DOS) : (DNS:DYNAMICUPDATE) : (DNS:EXPLOIT:BIND-KEYPARSE-DOS) : (DNS:EXPLOIT:BIND-OPENPGPKEY-DOS) : (DNS:EXPLOIT:CLIBCVE-2015-7547BO) : (DNS:EXPLOIT:ISC-BIND-DNS64-RPZ) : (DNS:EXPLOIT:LIBCVE-2015-7547BO2) : (DNS:EXPLOIT:MS-WIN-NAT-HLPR-DOS) : (DNS:ISC-BIND-ANY-DOS) : (DNS:ISC-BIND-ASSERT-DOS) : (DNS:ISC-BIND-CNAME-DNAME-DOS) : (DNS:ISC-BIND-CVE-2016-9444-DOS) : (DNS:ISC-BIND-DNSSEC-DOS) : (DNS:ISC-BIND-DOS) ……