Bad IP Address Feed
A bad IP address feed is a 32-bit binary number that represents a location on the internet. Criminals use IP addresses to spoof or phish for credentials, distribute malware, conduct denial of service attacks and run bots, port scans, and password brute force attempts on a target. These activities have a direct impact on a business’ ability to communicate with customers, partners and employees. Many security teams rely on reputation services to provide basic scoring of an IP address, but this often falls short in providing the visibility needed to respond to threats.
How a Bad IP Address Feed Can Help Prevent Network Attacks
This feed shares information about current and prevalent malicious IPs and data associated with them. This data is typically grouped into categories like comment spammers, dictionary attackers, mail servers, or other common behaviors. It is also possible to lookup specific IP addresses using this feed and get a more detailed report on what they have done in the past. This kind of information can be very useful, especially since criminal IP addresses are reused so often – the same address that was used to phish for credentials today could be sending out the latest 0-day flash exploit tomorrow.
Palo Alto Networks recommends integrating this feed at the firewall, near the application and server environments, to block traffic to and from these high-risk IP addresses. In addition, integrating this feed into the ADC and then filtering traffic to and from it will help to ensure that if an attack bypasses perimeter defenses, these IPs will be blocked before they can access critical applications and servers.…


