<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic In CSA 4.5, multiple various apps injecting code into a single specific in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/in-csa-4-5-multiple-various-apps-injecting-code-into-a-single/m-p/746728#M86692</link>
    <description>&lt;P&gt;In CSA 4.5, multiple various apps injecting code into a single specific process or application. Is there a way to stop &amp;lt;all apps&amp;gt; from injecting code into ONLY one specific application?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have over 500 events a day as a System API block &amp;lt;all applications&amp;gt; from injecting code into a single specific process.  The process (or app) is a Unix Emulation piece. It is called ReflectionX if anyone knows it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like there isn't a way to put in a HPDeny so that it will stop logging. I am not worried about it, however other security people here feel that it is in someway hurting the application.  It is very strange that all these various apps are targeting this single process the most. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does one do? &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:36:55 GMT</pubDate>
    <dc:creator>catherine.bacsak</dc:creator>
    <dc:date>2019-03-10T10:36:55Z</dc:date>
    <item>
      <title>In CSA 4.5, multiple various apps injecting code into a single specific</title>
      <link>https://community.cisco.com/t5/network-security/in-csa-4-5-multiple-various-apps-injecting-code-into-a-single/m-p/746728#M86692</link>
      <description>&lt;P&gt;In CSA 4.5, multiple various apps injecting code into a single specific process or application. Is there a way to stop &amp;lt;all apps&amp;gt; from injecting code into ONLY one specific application?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have over 500 events a day as a System API block &amp;lt;all applications&amp;gt; from injecting code into a single specific process.  The process (or app) is a Unix Emulation piece. It is called ReflectionX if anyone knows it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like there isn't a way to put in a HPDeny so that it will stop logging. I am not worried about it, however other security people here feel that it is in someway hurting the application.  It is very strange that all these various apps are targeting this single process the most. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does one do? &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:36:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-csa-4-5-multiple-various-apps-injecting-code-into-a-single/m-p/746728#M86692</guid>
      <dc:creator>catherine.bacsak</dc:creator>
      <dc:date>2019-03-10T10:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: In CSA 4.5, multiple various apps injecting code into a sing</title>
      <link>https://community.cisco.com/t5/network-security/in-csa-4-5-multiple-various-apps-injecting-code-into-a-single/m-p/746729#M86693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There really isn't a good way with this particular rule.  If it is a finite list of apps trying to inject code into r1win.exe, you could create an app class and add it to the exceptions list that are allowed to do this.  Not the best security practice especially if it includes apps like iexplore.exe, winword.exe, etc..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another method might be to use a Dynamic Application Class.  Set it up so that whenever Reflections does "X", all applications are allowed to inject code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would be a bit trickier since you have to analyse what causes the process in the first place and have it trigger the exception.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 May 2007 17:49:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/in-csa-4-5-multiple-various-apps-injecting-code-into-a-single/m-p/746729#M86693</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2007-05-18T17:49:07Z</dc:date>
    </item>
  </channel>
</rss>

