Skip to end of metadata
Go to start of metadata

You are viewing an old version of this content. View the current version.

Compare with Current View Version History

« Previous Version 9 Next »

In preparation of the August 2023 feed changes, Infoblox recommends the following rule action changes to your feed policy rules. 

Advisory

For information on recommended rule actions to be applied to feeds as replacement to the deprecated SURBL feeds, see Recommended Feed Configuration to Replace the SURBL Feeds

Alert

New feed recommendations: It is recommended that you do the following regarding the new feeds:

  • Add Suspicious Domains with one of the policy actions to Block.
  • Add Suspicious Lookalikes with one of the policy actions to  Block.
  • Add Suspicious NOED with one of the policy actions to  Block.

The following table includes the list of feeds that we will be retiring:

Feed

RPZ Name

Retirement Date

Reason

Bot-IP

bot-ip.rpz.infoblox.local

4/1/2023

IP addresses are frequently reused for multiple sites, and blocking the ones associated with such systems ran the high risk of inadvertent blocking (I.E. False Positive). Many indicators here could be blocked in other ways, so the source is blocked in other similar feeds, making this redundant.

Spambot-IP

spambot-ip.rpz.infoblox.local

4/1/2023

ExploitKit_IP

exploitkit-ip.rpz.infoblox.local

June 2023

Ext_ExploitKit_IP

ext-exploitkit-ip.rpz.infoblox.local

June 2023

Ext_TOR_Exit_Node_IP 

ext-tor-exit-node-ip.rpz.infoblox.local

June 2023

NCCIC_Host

nccic-host.rpz.infoblox.local

June 2023

The curation process for these feeds (I.E. removing false positives) frequently left these feeds empty. The ones that remained are present in other feeds, making these feeds redundant.

NCCIC_IP

nccic-ip.rpz.infoblox.local

June 2023


As these feeds are being retired, NIOS platforms will no longer be able to download them.  This may present itself as a problem with the Zone transfer. To avoid this issue, these feeds should be removed as soon as possible. As they have been empty for a long time, there will be no negative effect on the organization’s security posture. This only affects NIOS platforms using these RPZ feeds, as cloud-based configurations are updated automatically.  


For information on adding and removing feeds from a security policy, see the following: 


 Feed Precedence Order

  • When configuring feed precedence order, Please remember to prioritize feeds configured with a Block action (Block - No Redirect, Block - Default Redirect, and/or Block - Redirect - <custom redirect name>) by placing them in positions of higher precedence in your policy compared to feeds configured with an Allow action (Allow - With Log, Allow - No Log, and/or Allow - Local Resolution).Placing Blocked feeds higher in policy precedence order than Allowed feeds ensures that your security policy performs as intended.
  • Ensure that you understand the ramification of overriding the default action for any threat feeds and Threat Insight rules before doing so.


The following table lists the default actions and precedence for the feeds and Threat Insight in the Default Global Policy available May 2024:

Feed NameDefault ActionDefault Precedence
Default Allow ListAllow - No Log1
Default Bloxk ListBlock  – No Redirect2
Infoblox BaseBlock  – No Redirect3
Infoblox Base IPBlock  – No Redirect4
Infoblox High RiskBlock  – No Redirect5
Threat Insight - Zero Day DNSBlock  – No Redirect6
Infoblox Medium RiskBlock  – No Redirect7
Threat insight - DGAAllow – With Log8
Threat Insight-Data ExfiltrationAllow – With Log9
Threat Insight-Fast FluxAllow – With Log10
Threat Insight-DNS MessengerAllow – With Log11
Infoblox Low RiskAllow – With Log12
Infoblox InformationalAllow – With Log13
Threat insight - Notional Data ExfiltrationAllow – With Log14


The following table lists the default actions and precedence for the feeds and Threat Insight in the Default Global Policy (deprecated May 2024):

Feed NameDefault ActionDefault Precedence
Base HostnamesBlock  – No Redirect1
AntiMalwareBlock  – No Redirect2
Malware_DGA HostnamesBlock  – No Redirect3
RansomwareBlock  – No Redirect4
Public_DOHBlock  – No Redirect5
Public_DOH_IPBlock  – No Redirect6
DomainAllow – With Log7
Threat Insight-Data ExfiltrationAllow – With Log8
Threat Insight - Notional Data Exfiltration Allow – With Log9
Threat Insight-Fast FluxAllow – With Log10
Threat Insight-DNS MessengerAllow – With Log11
AntiMalware_IPAllow – With Log12
Ext_Base_AntiMalwarAllow – With Log13
Ext_RansomwareAllow – With Log14
Ext_AntiMalware_IPAllow – With Log15
DHS_AIS_DomainAllow – With Log16
CryptoCurrencyAllow – With Log17
TOR_Exit_Node_IPAllow – With Log18

For information on adding and removing feeds from a security policy, see the following: 

  • No labels