icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

FIX client LOGON detection

Info

Synopsis

The remote host is running the Financial Information eXchange (FIX) protocol.

Description

The remote client is running a Financial Information eXchange (FIX) application. This protocol is used by financial institutions to exchange data. The FIX protocol has very few built-in security controls and, instead, relies on industry standard encryption (PGP, SSL/TLS, etc.) to protect the stream. The PVS has just observed this client initiate a LOGON request without encryption set.

Solution

Ensure that FIX data is encrypted when passed over untrusted networks.