Azure Firewall IDPS Signature Constantly Updating

Yang, Steven 151 Reputation points
2023-10-06T17:01:14.1933333+00:00

I noticed that signatures in idps would some time update in a large quantity, and most of them are existing signature.

I'm trying to put down a process where the engineering would put the signature in monitor mode for certain # of days before go into deny mode. With signatures constantly updating in large quantity, i feel this is unmanageable. what are the best practices around managing signatures so I don't get hit with large quantity of false-positive

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
781 questions
{count} votes

1 answer

Sort by: Most helpful
  1. KapilAnanth-MSFT 49,616 Reputation points Microsoft Employee Moderator
    2023-10-09T04:16:28.5866667+00:00

    @Yang, Steven

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to understand the best practices with managing signatures in Azure Firewall.

    Can you please let me know what do you mean by "idps would some time update in a large quantity" ?

    • Do you mean that the new rules are being introduced?
    • or that the definition of a single rule gets updated ?

    Every signature would belong to a Group or Category.

    User's image

    While it may be the case that a signature's definition may get updated or new definitions will be introduced,

    • But their effect would still be the same (somewhat enhanced)
    • Based on their group/category, they will still target the same vulnerability as before the update, just that they will be now more enhanced.

    I don't think that a signature's definition or ID will be updated so that it's category itself would be changed.

    So, I doubt there will be a large quantity of false-positive as you described.

    Please let me know if you need more details on this.

    Cheers,

    Kapil

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.