Configuring Reverse Shell Detection and Defense
Scenario
In enterprise network environments, traditional security measures often fall short in defending against increasingly sophisticated network attacks, particularly reverse shell attacks. CFW defends against reverse shell attacks. After this function is enabled, the service can block reverse shells.
This section describes how to configure reverse shell detection and defense.
Notes and Constraints
- Intrusion prevention does not support decryption detection and defense for TLS- and SSL-encrypted traffic.
Impacts on Services
If IPS basic protection is enabled, a range of possible threats and suspicious traffic will be blocked. To change the protection mode, you are advised to enable the Observe mode and check false alarms for a period of time and then switch to the Intercept mode.
Actions
- Observe: If the firewall detects a reverse shell attack, it only records the attack in Viewing Attack Event Logs.
- Block session: If the firewall detects a reverse shell attack, it blocks the current session.
- Block IP: If CFW detects a reverse shell attack, it blocks the attack IP address for a period of time.
After Block IP is configured, CFW continuously blocks IP addresses. If address translation or proxy is involved, evaluate the impact of blocking IP addresses with caution.
Enabling Reverse Shell Defense
- Enable at least one type of traffic protection.
- For details about how to enable EIP traffic protection, see Enabling Internet Border Traffic Protection.
- For details about how to enable VPC traffic protection, see Enabling VPC Border Traffic Protection.
- For details about how to enable traffic protection for private IP addresses, see Enabling NAT Gateway Traffic Protection.
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose .
- Ensure Basic Protection is enabled.
- In the Reverse Shell Defense area, click the toggle button. The configuration page will be displayed.
- On the Reverse Shell Defense page, configure the action and protection mode.
Table 1 Reverse shell detection Parameter
Description
Action
- Observe: If the firewall detects a reverse shell attack, it only records the attack in Viewing Attack Event Logs.
- Block session: If the firewall detects a reverse shell attack, it blocks the current session.
- Block IP: If CFW detects a reverse shell attack, it blocks the attack IP address for a period of time. NOTE:
After Block IP is configured, CFW continuously blocks IP addresses. If address translation or proxy is involved, evaluate the impact of blocking IP addresses with caution.
Duration
If Action is set to Block IP, you can set the blocking duration. The value range is 60s to 3,600s.
Mode
- Conservative: coarse-grained protection. If a single session is attacked for four times, observation or interception is triggered. It ensures that no false positives are reported.
- Sensitive: fine-grained protection. If a single session is attacked for two times, observation or interception is triggered. It ensures that attacks can be detected and handled.
- Click OK.
Follow-up Operations
For details about the protection overview, see Event Center. For details about logs, see Viewing Attack Event Logs.
Related Operations
- Changing the defense action: Click Configure in the Reverse Shell Defense area. In the displayed dialog box, select an action and click OK.
- Modifying the threshold: Click Configure in the Reverse Shell Defense area. In the displayed dialog box, set the threshold and click OK.
- Disabling reverse shell defense: Click
next to Reverse Shell Defense. In the displayed dialog box, click OK.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot