4.17.2. MSRPC network traffic analysis in Network Intrusion Prevention Systems
Because of the numerous vulnerabilities discovered in MSRPC (see Section 4.16, “MSRPC vulnerabilities”), Network Intrusion Prevention and Detection
Systems must inspect MSRPC traffic to detect or block malicious traffic.
Because the protocols involved (SMB, MSRPC) are complex, implementation of
MSRPC traffic analysis in a network security device is a complex task that
requires a good understanding of the protocols. Several evasion techniques are
possible if the implementation of these protocols is not complete.
The successive improvements in NFR's MSRPC package gives a good idea of the work required to successfully implement MSRPC in NIPS:
- RAPID RESPONSE - MSRPC Version 21 (MS06-018 and Feature Upgrades): MSRPC package, version 21.
- MAINTENANCE - MSRPC Version 20: MSRPC package, version 20.
- RAPID RESPONSE - MSRPC Version 19 (MS05-047 and MS05-051): MSRPC package, version 19.
- RAPID RESPONSE: MSRPC Version 18 for MS05-039 (UPnP) exploit: MSRPC package, version 18.
- Beyond "Blaster" - MSRPC Evasions: nfr(sensor), June 2005.
- UPDATE - MSRPC Version 16: MSRPC package, version 16.
- MAINTENANCE - MSRPC Update (Version 15): MSRPC package, version 15.
- RAPID RESPONSE - MSRPC Update (v14) for MS05-007 and MS05-010 Microsoft vulnerabilities: MSRPC package, version 14.
- MAINTENANCE: Updated SMB Version 5 and MSRPC Version 13 packages available: MSRPC package, version 13.
- MAINTENANCE - MSRPC Update (Version 11) and SMB Update (Version 3): MSRPC package, version 11.
- Blasting "Blaster"-Detecting the MSRPC DCOM hole: nfr(sensor), fall 2003
- MSRPC Package Update - New Version of MSRPC (Version 10) Contains Important Bugfixes: MSRPC package, version 10.
- Important MSRPC DCOM package update - MS Messenger Service (MS03-043): MSRPC package, version 9.
- Important Note for all customers - MSRPC DCOM Rapid Response Update (Version 8): MSRPC package, version 8.
- Important Note for all customers - MSRPC DCOM Rapid Response Update: MSRPC package, version 7.
- Important Note for all customers - MSRPC DCOM Rapid Response Update: MSRPC package, version 6.
- DCOM Worm/MSRPC Update for NID-100 and NID-200 Customers: MSRPC package, version 5.
- UPDATED MS-RPC Rapid Response from NFR RRT: MSRPC package, version 4.
- UPDATED MS-RPC Rapid Response from NFR RRT: MSRPC package, version 2.
- NEW Package available to detect MSRPC DoS: MSRPC package, version 1.