Palo Alto Networks防病毒配置文件中误报的分类和解决
161731
Created On 09/26/18 19:13 PM - Last Modified 09/16/25 15:18 PM
Symptom
A benign file is detected as malicious.
Environment
- 所有 PAN-OS 版本。
Cause
The Antivirus profile on Palo Alto Networks firewalls is designed to block malicious files. However, benign files may occasionally be incorrectly blocked.
笔记
1. 对文件完整性的信心: This triage assumes that the file comes from a trusted source and is highly likely to be benign.
2.威胁日志相关性: This triage applies only to threat log entries with the types 'antivirus' or 'wildfire-virus'. It does not apply to entries of type 'ml-virus', 'spyware', or 'vulnerability'.
3. VirusTotal 指南: VirusTotal results are a useful reference but not definitive in all cases.
场景
场景 0: Dynamic Updates Not Current, Signature Already Disabled
Sometimes, a false positive affects multiple customers, and the problematic signature has already been disabled. Ensure that your Dynamic Updates schedule is properly configured.
场景 1: False Positive Due to Incorrect WildFire Verdict
A benign file analyzed by WildFire was incorrectly classified as malicious, leading to an Antivirus signature being created based on this incorrect verdict.
场景 2: Signature Collision with an Incorrect WildFire Verdict
Other benign files (with different SHA256 hashes) are flagged because their binary structure matches the signature of a file incorrectly classified as malicious (from Scenario 1).
场景 3: Signature Collision with a WildFire True Positive
A benign file is blocked because its binary structure matches that of a file correctly classified as malicious.
如何识别场景
1.检查签名是否被禁用:
- 威胁日志:如果日志显示威胁名称为“未知”,则该签名可能已被禁用。名称字段通过 API 查询填充,禁用签名可能会导致威胁日志没有名称。
- 威胁库:禁用的签名通常显示为“威胁 ID:n/a”和“当前版本:n/a”,这意味着该签名不再存在于内容更新中,但可能仍在 WildFire Real-Time 中处于活动状态。
- API 查询:威胁 ID 的威胁库API 查询可能显示“非活动”状态,这意味着签名在内容更新或 WildFire Real-Time 中不可用,因此这是场景 0。
3. 在威胁库中搜索: Look up the Threat ID in Threat Vault.
4.SHA256哈希值列表: Threat Vault will show a list of SHA256 hashes for files with a WildFire malicious verdict that match the signature pattern.
5. VirusTotal搜索:
- 如果所有哈希的检测计数都较低(例如,3 或更少,+评估其元数据:流行度、评论和引擎信誉以得出结论),那么这很可能是场景 2。
- 如果任何哈希具有较高的检测计数(例如,4 或更多+并且提供的元数据足以确定哈希是恶意的),那么这很可能是场景 1 或 3。
- 如果在 VirusTotal 上未找到哈希值,则可能是情况 2 或 3。
- 计算触发签名的文件的 SHA256 哈希值并在威胁库中检查它。
- 如果 WildFire 判定为恶意,而您确信该文件是良性的,则这是场景 1。
- 如果 WildFire 判定为良性,或文件哈希值未在威胁库中列出,则表示已确认签名冲突(场景 2 或 3)。请与 VirusTotal 数据进行交叉比对,以了解更多信息。
Resolution
Additional Information
Related articles:
什么是签名碰撞?
了解防病毒和野火事件中的文件哈希日志记录
WildFire 报告错误判决(病毒假阳性或假阴性)
如何使用反间谍软件、漏洞和防病毒例外来阻止或允许威胁
如何验证状态并排除 WildFire 实时签名更新功能故障