McAfee HISCDE-AB-IA Product Guide - Page 27

Host IPS protection updates, Checking in update packages

Page 27 highlights

Managing Your Protection System management Properties Process ID Protocol Remote IP Address Workstation Name Value Path of a threat source executable IP protocol (UDP, TCP, ICMP) Remote IP address of the system involved in the event Name of the system involved in the event Host IPS protection updates Host Intrusion Prevention supports multiple versions of client content and code, with the latest available content appearing in the ePO console. New content is always supported in subsequent versions, so content updates contain mostly new information or minor modifications to existing information. Updates are handled by a content update package. This package contains content version information and updating scripts. Upon check-in, the package version is compared to the version of the most recent content information in the database. If the package is newer, the scripts from this package are extracted and executed. This new content information is then passed to clients at the next agent-server communication. Updates include data associated with the IPS Rules policy (IPS signatures and application protection rules) and the Trusted Applications policy (trusted applications). As these updates occur in the McAfee default policy, these policies must be assigned for both IPS Rules and Trusted Applications to take advantage of the updated protection. The basic process includes checking in the update package to the ePO master repository, then sending the updated information to the clients. Clients obtain updates only through communication with the ePO server, and not directly through FTP or HTTP protocols. TIP: Always assign the McAfee Default IPS Rules policy and McAfee Default Trusted Applications policy to benefit from any content updates. If you modify these default policies, the modification is not overwritten with an update because modified settings in these policies take precedence over default settings. Checking in update packages You can create an ePO pull task that automatically checks in content update packages to the master repository. This task downloads the content update package directly from McAfee at the indicated frequency and adds it to the master repository, updating the database with new Host Intrusion Prevention content. Task 1 Click Menu | Software | Master Repository, then click Actions |Schedule Pull. 2 Name the task, for example, HIP Content Updates, then click Next. 3 Select Repository Pull as the task type, the source of the package (McAfeeHttp or McAfeeFtp), the branch to receive the package (Current, Previous, Evaluation), and a selected package (Host Intrusion Prevention Content), then click Next. 4 Schedule the task as needed, then click Next. 5 Verify the information, then click Save. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 27

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Value
Properties
Path of a threat source executable
Process ID
IP protocol (UDP, TCP, ICMP)
Protocol
Remote IP address of the system involved in the event
Remote IP Address
Name of the system involved in the event
Workstation Name
Host IPS protection updates
Host Intrusion Prevention supports multiple versions of client content and code, with the latest
available content appearing in the ePO console. New content is always supported in subsequent
versions, so content updates contain mostly new information or minor modifications to existing
information.
Updates are handled by a content update package. This package contains content version
information and updating scripts. Upon check-in, the package version is compared to the version
of the most recent content information in the database. If the package is newer, the scripts
from this package are extracted and executed. This new content information is then passed to
clients at the next agent-server communication.
Updates include data associated with the IPS Rules policy (IPS signatures and application
protection rules) and the Trusted Applications policy (trusted applications). As these updates
occur in the McAfee default policy, these policies must be assigned for both IPS Rules and
Trusted Applications to take advantage of the updated protection.
The basic process includes checking in the update package to the ePO master repository, then
sending the updated information to the clients. Clients obtain updates only through
communication with the ePO server, and not directly through FTP or HTTP protocols.
TIP:
Always assign the McAfee Default IPS Rules policy and McAfee Default Trusted Applications
policy to benefit from any content updates. If you modify these default policies, the modification
is not overwritten with an update because modified settings in these policies take precedence
over default settings.
Checking in update packages
You can create an ePO pull task that automatically checks in content update packages to the
master repository. This task downloads the content update package directly from McAfee at
the indicated frequency and adds it to the master repository, updating the database with new
Host Intrusion Prevention content.
Task
1
Click
Menu | Software | Master Repository
, then click
Actions |Schedule Pull
.
2
Name the task, for example,
HIP Content Updates
, then click
Next
.
3
Select
Repository Pull
as the task type, the source of the package (
McAfeeHttp
or
McAfeeFtp
), the branch to receive the package (
Current, Previous, Evaluation
), and
a selected package (
Host Intrusion Prevention Content
), then click
Next
.
4
Schedule the task as needed, then click
Next
.
5
Verify the information, then click
Save
.
Managing Your Protection
System management
27
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5