DSOP enables third parties (Tenable, Rapid7, Qualys, ServiceNow, etc) to easily apply and remove Deep Security IPS rules (virtual patches). Simply pass DSOP the:
DSOP takes the following required parameters:
- Hostname of a Deep Security protected host
- CVE of a vulnerability
And the following optional parameters:
- Deep Security policy name
- If a policy name is not provided, DSOP will fallback to using the host's currently applied policy
- If the provided policy name does not exist, DSOP will create it
- Whether to
enableordisablerules (defaults toenable) - Log level (defaults to
INFO)
DSOP will then do the following:
- Check if the specified policy name exists. If it doesn't, DSOP will create it. If no policy name was provided, the host's existing policy will be used
- Check if the policy already has rule(s) applied which protect against the specified CVE
- Check if the host is protected by the specified policy. If it isn't, DSOP changes the host's policy to match the specified policy
- Check if the policy has rule(s) applied which protect against the specified CVE
- If it does, DSOP removes the applied rule(s)
Provided payload:
{
'hostname': 'WIN-Q0HITV3HJ6D',
'policy_name': 'Demo Policy',
'cve': 'CVE-2016-2118',
'enable_rules': 'true', #optional - defaults to 'true'
'log_level': 'INFO' # optional - defaults to 'INFO'
}
In this run, Demo Policy is created, the relevant IPS rules are applied to it and the host is assigned the newly created policy.
17-Oct-19 16:26:59 - INFO - Obtaining DS API key
17-Oct-19 16:26:59 - INFO - Set API version to v1
17-Oct-19 16:26:59 - INFO - Obtained DS API address: https://app.deepsecurity.trendmicro.com/api
17-Oct-19 16:26:59 - INFO - Initiating DS connection
17-Oct-19 16:26:59 - INFO - Received CVE-2016-2118 and "WIN-Q0HITV3HJ6D" for policy "Demo Policy"
17-Oct-19 16:26:59 - INFO - Obtaining IPS rules...
17-Oct-19 16:27:03 - INFO - Found 5000 rules
17-Oct-19 16:27:05 - INFO - Found 2005 rules
17-Oct-19 16:27:05 - INFO - Total IPS rules found: 7005
17-Oct-19 16:27:09 - INFO - Mapping CVEs to IPS rules
17-Oct-19 16:27:09 - INFO - Searching for "Demo Policy" policy ID...
17-Oct-19 16:27:09 - INFO - Policy name "Demo Policy" does not exist. Creating it...
17-Oct-19 16:27:10 - INFO - Policy "Demo Policy" created successfully. Policy ID: 54
17-Oct-19 16:27:10 - INFO - CVE-2016-2118 maps to IPS rule(s): 4456, 4458, 4459, 4460, 4461
17-Oct-19 16:27:10 - INFO - Checking if rule(s) already applied to the "Demo Policy" policy...
17-Oct-19 16:27:10 - INFO - Rules which need to be applied: 4456, 4458, 4459, 4460, 4461
17-Oct-19 16:27:10 - INFO - Successfully applied new rule(s)
17-Oct-19 16:27:10 - INFO - Now checking if "WIN-Q0HITV3HJ6D" is covered by policy "Demo Policy"
17-Oct-19 16:27:10 - INFO - Searching for "WIN-Q0HITV3HJ6D" IDs...
17-Oct-19 16:27:11 - INFO - "WIN-Q0HITV3HJ6D" - Computer ID: 34, Policy ID: 53
17-Oct-19 16:27:11 - INFO - "WIN-Q0HITV3HJ6D" Policy ID (53) does not match "Demo Policy" Policy ID (54)
17-Oct-19 16:27:13 - INFO - Successfully moved "WIN-Q0HITV3HJ6D" to Policy "Demo Policy"
17-Oct-19 16:27:13 - INFO - Finished
Re-running the script results in no changes, as everything is already in place:
17-Oct-19 16:27:34 - INFO - Obtaining DS API key
17-Oct-19 16:27:34 - INFO - Set API version to v1
17-Oct-19 16:27:34 - INFO - Obtained DS API address: https://app.deepsecurity.trendmicro.com/api
17-Oct-19 16:27:34 - INFO - Initiating DS connection
17-Oct-19 16:27:34 - INFO - Received CVE-2016-2118 and "WIN-Q0HITV3HJ6D" for policy "Demo Policy"
17-Oct-19 16:27:34 - INFO - Obtaining IPS rules...
17-Oct-19 16:27:38 - INFO - Found 5000 rules
17-Oct-19 16:27:40 - INFO - Found 2005 rules
17-Oct-19 16:27:40 - INFO - Total IPS rules found: 7005
17-Oct-19 16:27:44 - INFO - Mapping CVEs to IPS rules
17-Oct-19 16:27:44 - INFO - Searching for "Demo Policy" policy ID...
17-Oct-19 16:27:44 - INFO - Policy found - Policy ID: 54, Applied IPS rule IDs: 4456, 4458, 4459, 4460, 4461
17-Oct-19 16:27:44 - INFO - CVE-2016-2118 maps to IPS rule(s): 4456, 4458, 4459, 4460, 4461
17-Oct-19 16:27:44 - INFO - Checking if rule(s) already applied to the "Demo Policy" policy...
17-Oct-19 16:27:44 - INFO - All required IPS rules are already applied. No policy modifications are required
17-Oct-19 16:27:44 - INFO - Now checking if "WIN-Q0HITV3HJ6D" is covered by policy "Demo Policy"
17-Oct-19 16:27:44 - INFO - Searching for "WIN-Q0HITV3HJ6D" IDs...
17-Oct-19 16:27:45 - INFO - "WIN-Q0HITV3HJ6D" - Computer ID: 34, Policy ID: 54
17-Oct-19 16:27:45 - INFO - "WIN-Q0HITV3HJ6D" is already covered by policy "Demo Policy". No computer modifications are required
17-Oct-19 16:27:45 - INFO - Finished
Adding a new CVE results in additional IPS rule(s) being applied:
17-Oct-19 16:28:16 - INFO - Obtaining DS API key
17-Oct-19 16:28:16 - INFO - Set API version to v1
17-Oct-19 16:28:16 - INFO - Obtained DS API address: https://app.deepsecurity.trendmicro.com/api
17-Oct-19 16:28:16 - INFO - Initiating DS connection
17-Oct-19 16:28:16 - INFO - Received CVE-2017-0148 and "WIN-Q0HITV3HJ6D" for policy "Demo Policy"
17-Oct-19 16:28:16 - INFO - Obtaining IPS rules...
17-Oct-19 16:28:20 - INFO - Found 5000 rules
17-Oct-19 16:28:22 - INFO - Found 2005 rules
17-Oct-19 16:28:22 - INFO - Total IPS rules found: 7005
17-Oct-19 16:28:27 - INFO - Mapping CVEs to IPS rules
17-Oct-19 16:28:27 - INFO - Searching for "Demo Policy" policy ID...
17-Oct-19 16:28:27 - INFO - Policy found - Policy ID: 54, Applied IPS rule IDs: 4456, 4458, 4459, 4460, 4461
17-Oct-19 16:28:27 - INFO - CVE-2017-0148 maps to IPS rule(s): 6281, 6282, 6298, 6308
17-Oct-19 16:28:27 - INFO - Checking if rule(s) already applied to the "Demo Policy" policy...
17-Oct-19 16:28:27 - INFO - Rules which need to be applied: 6281, 6282, 6308, 6298
17-Oct-19 16:28:28 - INFO - Successfully applied new rule(s)
17-Oct-19 16:28:28 - INFO - Now checking if "WIN-Q0HITV3HJ6D" is covered by policy "Demo Policy"
17-Oct-19 16:28:28 - INFO - Searching for "WIN-Q0HITV3HJ6D" IDs...
17-Oct-19 16:28:28 - INFO - "WIN-Q0HITV3HJ6D" - Computer ID: 34, Policy ID: 54
17-Oct-19 16:28:28 - INFO - "WIN-Q0HITV3HJ6D" is already covered by policy "Demo Policy". No computer modifications are required
17-Oct-19 16:28:28 - INFO - Finished
When a known CVE is provided, the Lambda returns the following JSON payload:
{
"statusCode": 200,
"body": "\"Successfully moved WIN-Q0HITV3HJ6D to Policy Demo Policy\""
}
When an unknown CVE is provided, the Lambda returns the following JSON payload:
{
"statusCode": 400,
"body": "Cannot find an IPS rule for CVE-2014-3568000"
}
{
"statusCode": 200,
"body": "\"Rules are not applied to policy. No changes need to be made\""}
There are two ways in which DSOP can be deployed:
- As a standalone Lambda
- As a Lambda which is subscribed to an SNS topic
Both options are described below.
- Create an S3 bucket which will be used to store your Lambda.
- Zip & upload the Lambda:
cd code
rm -rf libs/__pycache__/
pip3 install -r requirements.txt --target ./package
cd package
zip -r9 ../deep-security-open-patch.zip .
cd ..
zip -g deep-security-open-patch.zip dsop.py
aws s3 cp deep-security-open-patch.zip s3://<LAMBDA_BUCKET_NAME>/deep-security-open-patch.zip
rm -rf deep-security-open-patch.zip package
- Deploy CloudFormation template:
cd ../cfn
aws cloudformation validate-template --template-body file://cfn.yaml
aws cloudformation create-stack \
--stack-name deep-security-open-patch-lambda \
--template-body file://cfn.yaml \
--parameters \
ParameterKey=LambdaBucketName,ParameterValue=<BUCKET_NAME> \
ParameterKey=LambdaS3KeyPath,ParameterValue=<S3_KEY_PATH> \
ParameterKey=DeepSecurityApiKey,ParameterValue=<API_KEY> \
ParameterKey=DeepSecurityAddress,ParameterValue=<API_ADDRESS> \
--capabilities CAPABILITY_IAM
Note that DeepSecurityAddress is optional. It is set to https://app.deepsecurity.trendmicro.com by default.
- Deploy CloudFormation template:
cd ../cfn
aws cloudformation validate-template --template-body file://cfn-sns.yaml
aws cloudformation create-stack \
--stack-name deep-security-open-patch-lambda-sns \
--template-body file://cfn-sns.yaml \
--parameters \
ParameterKey=LambdaBucketName,ParameterValue=<BUCKET_NAME> \
ParameterKey=LambdaS3KeyPath,ParameterValue=<S3_KEY_PATH> \
ParameterKey=DeepSecurityApiKey,ParameterValue=<API_KEY> \
ParameterKey=DeepSecurityAddress,ParameterValue=<API_ADDRESS> \
--capabilities CAPABILITY_IAM
Note that DeepSecurityAddress is optional. It is set to https://app.deepsecurity.trendmicro.com by default.
If you update the code, you'll need to update Lambda:
aws lambda update-function-code \
--function-name DeepSecurityOpenPatch \
--s3-bucket <BUCKET_NAME> \
--s3-key <S3_KEY_PATH>/deep-security-open-patch.zip
- Blog: oznetnerd.com
- Email: will@oznetnerd.com