4.1.1 Detect Botnet connections

Information

Interfaces which are classified as 'WAN' and are used by a policy should use an IPS sensor which blocks or monitors outgoing connections to botnet sites.

Rationale:

Blocking outgoing connections to known Botnets should be utilized in a Defense In Depth network design.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

On GUI:

1. Configure relevant IPS profiles with 'Scan Outgoing Connections to Botnet Sites' set to 'Block'.
2. Apply relevant IPS profile on all firewall policies with traffic exiting the network to a 'WAN' interface.

Default Value:

'Scan Outgoing Connections to Botnet Sites' is disabled on default profile.

See Also

https://workbench.cisecurity.org/benchmarks/12961

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, 800-53|SI-4(4)

Plugin: FortiGate

Control ID: 851ab0ba3daef6d33d40ca73c590ffca72ff02c7ccb2685243548828e309b51a