Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

SecIntel Feeds Overview

SecIntel feeds provide carefully curated and verified threat intelligence from the following sources:

  • Juniper ATP Cloud

  • Juniper Threat Labs

  • Dynamic Address Groups (DAG)

  • Industry-leading threat feeds

SecIntel delivers this intelligence to MX Series routers, SRX Series Firewalls, and NFX Series Network Services Platform to block command-and-control (C&C) communications at line rate. SecIntel enables automatic and responsive traffic filtering to deliver real-time threat intelligence.

SecIntel also integrates with EX Series and QFX Series switches to subscribe to SecIntel’s infected host feed. This integration enables you to block compromised hosts directly at the switch port.

Benefits of SecIntel Feeds

  • Real-time threat sharing—Delivers continuously updated threat intelligence to devices to block malicious traffic at line rate.

  • Support for multiple feed types—Supports Juniper-provided, third-party, and custom feeds with granular policy control for threat detection.

On the SecIntel Feeds page, you can view which SecIntel feeds are enabled. SecIntel feeds include threat feeds provided by Juniper Networks as described in Table 1.

Table 1: Juniper Threat Feeds

Feed

Description

Command and Control Feed

C&C feeds are lists of servers known to provide botnet command-and-control or to host malware downloads.

Malicious Domains (DNS)

List of domains that are known to be connected to malicious activity.

Infected Host Feed

Infected hosts are local devices that might be compromised because these devices appear to be part of a C&C network or show other signs of compromise.

By default, the Infected Host Feed is enabled for all license tiers and is supported only on SRX Series Firewalls. Other SecIntel feeds require a ThreatFeeds or Premium license. For more information about SecIntel feed licensing, see Software Licenses for ATP Cloud.

SRX Series Firewalls support all SecIntel feed categories, while MX Series routers support only C&C and GeoIP feeds.

You can enable the following feeds for integration with Juniper ATP Cloud:

  • Third Party Threat Feeds—IP and URL threat feeds

  • Dynamic Address Group Feeds—Juniper-provided and third-party DAG feeds.

For more information about configuring SecIntel feeds, see Configure SecIntel Feeds in Juniper ATP Cloud Portal.

The expiration of SecIntel feeds is determined by the time-to-live (TTL) value, which varies by the feed.