McAfee HISCDE-AB-IA Product Guide - Page 150

McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

Page 150 highlights

Index custom signatures (continued) Linux, UNIX_file (Files) 127 Linux, UNIX_misc 131 optional sections 104 overview for Linux and Solaris 127 overview for Windows 107 rule structure 101 section value variables 104 Solaris 127 Solaris, UNIX_apache (HTTP) 130 Solaris, UNIX_bo 132 Solaris, UNIX_file (Files) 127 Solaris, UNIX_GUID 133 Solaris, UNIX_map 133 Solaris, UNIX_misc 131 wildcards 104 Windows, Buffer Overflow 107 Windows, directives per platform 123 Windows, Files 108 Windows, Hook 111 Windows, Illegal 113 Windows, Illegal API Use 112 Windows, Isapi 113 Windows, Program 116 Windows, Registry 117 Windows, Services 120 Windows, SQL 122 D dashboards default Host IPS monitors 12 managing information in Host IPS 12 queries and Host Intrusion Prevention 10 viewing compliance and Host IPS issues 17 deployment Host IPS policies and 10 initial Host IPS client rollout 19 server tasks for Host IPS 23 usage profiles in Host IPS 10 DNS blocking rules creating and editing 70 E effective policy with multiple-instance policies 38 enveloping and shielding 30 events, Host IPS automatic responses 26 analyzing and tuning 10 automatic responses 26 behavioral rules 32 exceptions 32 firewall, activity logs 93 intrusion alerts, responding to 86 IPS Rules policy 36 logging and IPS Events tab 33 managing 48 signature violations 33 working with 47 exception rules about 32 aggregation and client rules 50 automatic tuning 20 configuring IPS Rules policy 46 Create Exception 86 exception rules (continued) creating 47 creating, based on an event 47 defined 10 editing IPS policies 89 events and 47 IPS Rules policy 36, 46 list, Windows client and 88 working with 46 F false positives exceptions and IPS Rules policy 46 Trusted Applications policy, reducing 78 tuning Host IPS policies 10 FAQ adaptive mode 21 multiple-instance policies 38 filters Host IPS events and queries 10 how firewall stateful filtering works 60 querying Host IPS activities 13 Firewall DNS Blocking policy about 8 define 67 overview 52 Firewall Options policy TrustedSource 66 about 8 configuring 65 overview 52 working with 64 Firewall policies, Host IPS feature overview 52 firewall protection disable 64 enable 64 firewall rules creating and editing 69 Firewall Rules policy wildcards 72 about 8 client rules, managing 71 configuring 68 define 67 groups, creating 69 overview 52 firewall, Host IPS stateful packet inspection 59, 61 about 8 actions, allow and block 60 alerts 87 client rules 13, 64 customizing options 90 DNS blocking rules 70 Firewall Options, configuring 65 firewall rule groups, creating 69 firewall rules 10, 67, 69 firewall rules list, ordering 53 Firewall Rules, configuring 68 how firewall rules work 53 learn and adaptive modes 63 list of rules 68, 89, 90 location-aware groups 70 logging options 85 150 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

custom signatures
(continued)
Linux, UNIX_file (Files)
127
Linux, UNIX_misc
131
optional sections
104
overview for Linux and Solaris
127
overview for Windows
107
rule structure
101
section value variables
104
Solaris
127
Solaris, UNIX_apache (HTTP)
130
Solaris, UNIX_bo
132
Solaris, UNIX_file (Files)
127
Solaris, UNIX_GUID
133
Solaris, UNIX_map
133
Solaris, UNIX_misc
131
wildcards
104
Windows, Buffer Overflow
107
Windows, directives per platform
123
Windows, Files
108
Windows, Hook
111
Windows, Illegal
113
Windows, Illegal API Use
112
Windows, Isapi
113
Windows, Program
116
Windows, Registry
117
Windows, Services
120
Windows, SQL
122
D
dashboards
default Host IPS monitors
12
managing information in Host IPS
12
queries and Host Intrusion Prevention
10
viewing compliance and Host IPS issues
17
deployment
Host IPS policies and
10
initial Host IPS client rollout
19
server tasks for Host IPS
23
usage profiles in Host IPS
10
DNS blocking rules
creating and editing
70
E
effective policy
with multiple-instance policies
38
enveloping and shielding
30
events, Host IPS
automatic responses
26
analyzing and tuning
10
automatic responses
26
behavioral rules
32
exceptions
32
firewall, activity logs
93
intrusion alerts, responding to
86
IPS Rules policy
36
logging and IPS Events tab
33
managing
48
signature violations
33
working with
47
exception rules
about
32
aggregation and client rules
50
automatic tuning
20
configuring IPS Rules policy
46
Create Exception
86
exception rules
(continued)
creating
47
creating, based on an event
47
defined
10
editing IPS policies
89
events and
47
IPS Rules policy
36
,
46
list, Windows client and
88
working with
46
F
false positives
exceptions and IPS Rules policy
46
Trusted Applications policy, reducing
78
tuning Host IPS policies
10
FAQ
adaptive mode
21
multiple-instance policies
38
filters
Host IPS events and queries
10
how firewall stateful filtering works
60
querying Host IPS activities
13
Firewall DNS Blocking policy
about
8
define
67
overview
52
Firewall Options policy
TrustedSource
66
about
8
configuring
65
overview
52
working with
64
Firewall policies, Host IPS
feature overview
52
firewall protection
disable
64
enable
64
firewall rules
creating and editing
69
Firewall Rules policy
wildcards
72
about
8
client rules, managing
71
configuring
68
define
67
groups, creating
69
overview
52
firewall, Host IPS
stateful packet inspection
59
,
61
about
8
actions, allow and block
60
alerts
87
client rules
13
,
64
customizing options
90
DNS blocking rules
70
Firewall Options, configuring
65
firewall rule groups, creating
69
firewall rules
10
,
67
,
69
firewall rules list, ordering
53
Firewall Rules, configuring
68
how firewall rules work
53
learn and adaptive modes
63
list of rules
68
,
89
,
90
location-aware groups
70
logging options
85
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
150
Index