Laporan Scanning Firewall Rri
Laporan Scanning Firewall Rri
Application Usage
The FortiGuard research team categorizes applications into
different categories based on the application behavioral Top Application Categories
characteristics, underlying technology, and the related traffic
transaction characteristics. The categories allow for better
application control. FortiGuard maintains thousands of
application sensors and can even perform deep application
inspection. For example, IT managers can get unprecedented unscanned = 3.9 TB(57.7%)
visibility into filenames sent to the cloud or the titles of videos
being streamed. video/audio = 779.5 GB(11.3%)
Sent Received
Page 1
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Page 2
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Page 3
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Web Activities
Identifying which web categories and websites are accessed by applications provides additional data points for administrators to
understand the network traffic usage. Defining appropriate application policies along with web filtering policies will greatly reduce the
business risk. Fortinet's proprietary web filtering database is developed by the FortiGuard research team. The database contains
more than 47 million rated websites with real-time updates; the websites are categorized into 76 web categories to allow highly-
granular web filtering policies.
33.2%
<N/A> = 388(44.6%)
Phishing = 289(33.2%)
Pornography = 75(8.6%)
8.6%
Gambling = 67(7.7%)
5.9%
Page 4
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Web Activities
Most Visited Web Categories and Web Sites
Category % Web Site % Visits Estimated Browsing
Time
<N/A> 44.6% 100% 388 00h 00m 00s
Phishing 33.2% ssp. swe.xyz 89.6% 259 00h 00m 00s
excretekings. com 4.8% 14 00h 00m 00s
cdrvrs. com 1.0% 3 00h 00m 00s
www. aversus.site 0.7% 2 00h 00m 00s
www. liveupdt.com 0.7% 2 00h 00m 00s
Other 3.1% 9 00h 00m 00s
Pornography 8.6% jb73i0. fsdgled.com 44.0% 33 00h 00m 00s
adserver. juicyads.com 20.0% 15 00h 00m 00s
wonporn. com 8.0% 6 00h 00m 00s
xnxx. com 5.3% 4 00h 00m 00s
a4442. com 5.3% 4 00h 00m 00s
Other 17.3% 13 00h 00m 00s
Gambling 7.7% app-api. charityengine.services 55.2% 37 00h 00m 00s
3ot8y. xikuj.com 23.9% 16 00h 00m 00s
sanxiao. iibingo.com 11.9% 8 00h 00m 00s
www. dafabet.com 4.5% 3 00h 00m 00s
match3games1. iibingo.com 3.0% 2 00h 00m 00s
Other 1.5% 1 00h 00m 00s
Spam URLs 5.9% xml-eu-v4. gipostart-1.co 82.4% 42 00h 00m 00s
feignthat. com 13.7% 7 00h 00m 00s
mipytj35. top 3.9% 2 00h 00m 00s
Total: 870
Visits
Page 5
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
30 percent of data breaches involve organization insiders acting negligently or maliciously. Insiders pose a unique threat to
organizations because they have access to proprietary systems and often are able to bypass security measures creating a security
blind spot to the risk and security teams. User Behavior Analytics protects organizations from insider threats by continuously
monitoring users and endpoints.
Active Users
Most Active Application Users
User %
Session
(UnauthUser)
N/A(N/A) 560110691 100.0%
Total: 560.1 M
Page 6
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Sent Received
Page 7
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Visits
Page 8
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Sent Received
Page 9
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Visits
Page 10
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
The rise of modern malware has reshaped the threat landscape. These modern threats bypass traditional antimalware strategies and
establish a foothold within the enterprise. They are used by criminals and nation-states to steal sensitive information and attack
assets. Fortinet next-generation firewall provides multi-level protection to combat these advanced persistent threat - the reliable
visibility and control of all traffic on the network regardless of evasive tactics. The FortiGuard AntiVirus Service employs advanced
virus, spyware, and heuristic detection engines to enable FortiGate systems to detect and prevent both new and evolving threats. For
AntiVirus see: http://www.fortiguard.com/antivirus/ .
Top Viruses
Virus Incidents %
FSA/RISK_HIGH-http 1322 76.1%
Riskware/Miner-http 213 12.3%
W32/Agent.OJQ!tr-http 121 7.0%
JS/ProxyChanger.GB!tr-http 39 2.2%
Android/HiddenApp.KN!tr-http 21 1.2%
JS/Redirector.0C36!tr-http 11 0.6%
FSA/RISK_MALICIOUS-http 4 0.2%
f244bfe57d2cbc83e4113b155c6b8f02676cb80e-http 2 0.1%
Adware/Pirrit!OSX-http 2 0.1%
Adware/DotSetupIo-http 1 0.1%
W64/Agent.FP!tr-http 1 0.1%
W32/Kryptik.HSDC!tr-http 1 0.1%
Page 11
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Total: 1738
Page 12
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Top Attacks
Attack ID Incidents %
MySQL.Login.Brute.Force 101008 82.5%
Backdoor.DoublePulsar 12427 10.2%
Andromeda.Botnet 3574 2.9%
SSLv3.POODLE.Information.Disclosure 3409 2.8%
Ramnit.Botnet 954 0.8%
MS.SMB.Server.Trans.Peeking.Data.Information.Disclosure 800 0.7%
TCP.Split.Handshake 117 0.1%
Conficker.Botnet 60 0.0%
Amadey.Botnet 42 0.0%
DCRat.Botnet 8 0.0%
Raccoon.Botnet 5 0.0%
MS.SMB.Server.SMB1.MID.FID.Parsing.Remote.Code....ution 2 0.0%
Oracle.MySQL.For.Windows.MOF.Execution 1 0.0%
Total: 122407
Page 13
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Page 14
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Applications that have the ability to transfer files can pose a significant risk of data loss: company's customer data, intellectual
property and confidential business trade secrets can be sent out of the organization via these applications. Knowing which types of
files and content are transferred crossing the network can help administrators to mitigate the risk by setting up appropriate
application policies along with data leak prevention rules on the Fortinet next-generation firewall system.
Page 15
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
FortiClient protects your endpoints with an extra layer of security; it's engineered to defeat the latest and most dangerous malware
and provides real-time protection on the company's desktops and mobile devices. FortiClient together with Fortinet next generation
Firewall delivers fully managed and layered security defences.
32.3%
Page 16
Device: FortiGate100F-RRI-Pusat(root)
2023-01-22 00:00 - 2023-01-29 00:00 Asia/Kolkata
Appendix:Devices
Report is generated from following devices:
FG100FTK22000969(root)
Page 17