I need a solution
Hello,
We have several PC's where SEP is blocking inbound Firewall Traffic on Chrome.
There are no plugins/add-ons installed. Nothing detected in Risks log. Threat Analysis as well does not show any suspicious files.
Could you please help me anylyzing the cause of it.
This is what I see in Traffic logs:
Time Stamp | Event Type | Event Time | Severity | Historical IP Address | Remote Host IP | Remote Host Name | Network Protocol | Local Port | Remote Port | Traffic Direction | Application Name | Begin Time | End Time | Repetition | ACTION | Rule Name | Alert | Send Snmp Trap | Local Host Mac | Remote Host Mac | Hardware Key | User Name |
08/31/2017 18:02:06 | UDP datagram | 08/31/2017 18:01:34 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 61608 | 42860 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 08:35:58 | 08/31/2017 08:35:58 | 1 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 18:02:06 | UDP datagram | 08/31/2017 08:35:57 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 61608 | 42860 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 08:35:58 | 08/31/2017 08:35:58 | 1 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 18:02:06 | UDP datagram | 08/31/2017 08:34:31 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 64504 | 42860 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 08:34:18 | 08/31/2017 08:34:18 | 1 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 18:02:06 | UDP datagram | 08/31/2017 08:30:31 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 64972 | 42860 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 08:30:18 | 08/31/2017 08:30:20 | 3 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 18:02:06 | UDP datagram | 08/31/2017 08:26:36 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 64964 | 42860 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 08:26:19 | 08/31/2017 08:26:22 | 4 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 18:02:06 | UDP datagram | 08/31/2017 08:22:31 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 61077 | 42860 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 08:22:20 | 08/31/2017 08:22:20 | 2 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 08:22:40 | UDP datagram | 08/31/2017 08:20:34 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 63656 | 42860 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 08:20:21 | 08/31/2017 08:20:21 | 2 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 08:22:40 | UDP datagram | 08/31/2017 08:16:34 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 62696 | 42860 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 08:16:18 | 08/31/2017 08:16:22 | 2 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 08:22:40 | UDP datagram | 08/31/2017 08:12:34 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 52160 | 42860 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 08:12:20 | 08/31/2017 08:12:20 | 1 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 08:22:40 | UDP datagram | 08/31/2017 07:56:35 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 58091 | 42860 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 07:56:19 | 08/31/2017 07:56:21 | 3 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 08:22:40 | UDP datagram | 08/31/2017 07:42:33 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 60060 | 57260 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 07:42:20 | 08/31/2017 07:42:20 | 1 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 08:22:40 | UDP datagram | 08/31/2017 07:34:33 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 55230 | 57260 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 07:34:22 | 08/31/2017 07:34:22 | 1 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 07:22:36 | UDP datagram | 08/31/2017 07:04:32 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 56023 | 59948 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 07:04:20 | 08/31/2017 07:04:21 | 3 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 07:22:36 | UDP datagram | 08/31/2017 07:00:32 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 53130 | 59948 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 07:00:18 | 08/31/2017 07:00:20 | 3 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 07:22:36 | UDP datagram | 08/31/2017 06:42:31 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 54804 | 59948 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 06:42:18 | 08/31/2017 06:42:18 | 1 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 07:22:36 | UDP datagram | 08/31/2017 06:38:31 | Critical | 192.168.0.17 | 192.168.0.13 | UDP | 53148 | 59948 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 06:38:19 | 08/31/2017 06:38:20 | 4 | Blocked | Block all incoming traffic to applications which isn´t approved | 0 | 0 | E4B3181DB537 | 44650D44EF10 | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 03:20:44 | UDP datagram | 08/31/2017 03:19:36 | Minor | ff02:0000:0000:0000:0000:0000:0000:00fb | fe80:0000:0000:0000:00e0:1fce:550e:bf93 | UDP | 5353 | 5353 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 03:19:25 | 08/31/2017 03:19:25 | 1 | Blocked | Block all other applications | 0 | 0 | 3333000000FB | 40331AE6DE0B | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 03:20:44 | UDP datagram | 08/31/2017 03:19:15 | Minor | ff02:0000:0000:0000:0000:0000:0000:00fb | fe80:0000:0000:0000:00e0:1fce:550e:bf93 | UDP | 5353 | 5353 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 03:19:12 | 08/31/2017 03:19:16 | 3 | Blocked | Block all other applications | 0 | 0 | 3333000000FB | 40331AE6DE0B | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 03:20:44 | UDP datagram | 08/31/2017 03:14:04 | Minor | ff02:0000:0000:0000:0000:0000:0000:00fb | fe80:0000:0000:0000:143d:1e54:1e18:28f9 | UDP | 5353 | 5353 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 03:13:57 | 08/31/2017 03:14:04 | 10 | Blocked | Block all other applications | 0 | 0 | 3333000000FB | BC9FEF04513A | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 03:20:44 | UDP datagram | 08/31/2017 03:13:38 | Minor | ff02:0000:0000:0000:0000:0000:0000:00fb | fe80:0000:0000:0000:00e0:1fce:550e:bf93 | UDP | 5353 | 5353 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 03:13:20 | 08/31/2017 03:13:24 | 3 | Blocked | Block all other applications | 0 | 0 | 3333000000FB | 40331AE6DE0B | D1683A5566288205E870EF2B7553FAB3 | ud5249v | |
08/31/2017 03:20:44 | UDP datagram | 08/31/2017 03:12:26 | Minor | ff02:0000:0000:0000:0000:0000:0000:00fb | fe80:0000:0000:0000:00e0:1fce:550e:bf93 | UDP | 5353 | 5353 | Inbound | C:/Program Files (x86)/Google/Chrome/Application/chrome.exe | 08/31/2017 03:12:12 | 08/31/2017 03:12:13 | 2 | Blocked | Block all other applications | 0 | 0 | 3333000000FB | 40331AE6DE0B | D1683A5566288205E870EF2B7553FAB3 | ud5249v |
0