McAfee HISCDE-AB-IA Product Guide - Page 35

Set the reaction for IPS signatures, Policy selections

Page 35 highlights

Configuring IPS Policies Set the reaction for IPS signatures Task For option definitions, click ? in the interface. 1 Click Menu | Policy | Policy Catalog and select Host Intrusion Prevention:IPS in the Product list and IPS Options in the Category list. The list of policies appears. 2 In the IPS Options policy list, click Edit under Actions to change the settings for a custom policy. NOTE: For editable policies, other options include: Rename, Duplicate, Delete, and Export. For non-editable policies, options include View and Duplicate. 3 In the IPS Options page that appears, make any needed changes, including status, startup, and network IPS settings, then click Save. Set the reaction for IPS signatures The IPS Protection policy sets the protective reaction for signature severity levels. These settings instruct clients what to do when an attack or suspicious behavior is detected. Each signature has one of four severity levels: • High - Signatures of clearly identifiable security threats or malicious actions. These signatures are specific to well-identified exploits and are mostly non-behavioral in nature. Prevent these signatures on every system. • Medium - Signatures of behavioral activity where applications operate outside their envelope. Prevent these signatures on critical systems, as well as on web servers and SQL servers. • Low - Signatures of behavioral activity where applications and system resources are locked and cannot be changed. Preventing these signatures increases the security of the underlying system, but additional fine-tuning is needed. • Information - Signatures of behavioral activity where applications and system resources are modified and might indicate a benign security risk or an attempt to access sensitive system information. Events at this level occur during normal system activity and generally are not evidence of an attack. These severity levels indicate potential danger to a system and enable you to define specific reactions for different levels of potential harm. You can modify the severity levels and reactions for all signatures. For example, when suspicious activity is unlikely to cause damage, you can select ignore as the reaction. When an activity is likely to be dangerous, you can set prevent as the reaction. Policy selections This policy category contains six preconfigured policies and an editable My Default policy, based on the McAfee Default policy. You can view and duplicate preconfigured policies; you can, create, edit, rename, duplicate, delete, and export custom policies. Preconfigured policies include: Table 6: IPS Protection policies Name Function Basic Protection (McAfee Default) Prevent high-severity signatures and ignore the rest. Enhanced Protection Prevent high- and medium-severity signatures and ignore the rest. McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 35

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Task
For option definitions, click
?
in the interface.
1
Click
Menu | Policy | Policy Catalog
and select
Host Intrusion Prevention:IPS
in
the
Product
list and
IPS Options
in the
Category
list. The list of policies appears.
2
In the
IPS Options
policy list, click
Edit
under
Actions
to change the settings for a custom
policy.
NOTE:
For editable policies, other options include: Rename, Duplicate, Delete, and Export.
For non-editable policies, options include View and Duplicate.
3
In the
IPS Options
page that appears, make any needed changes, including status, startup,
and network IPS settings, then click
Save
.
Set the reaction for IPS signatures
The IPS Protection policy sets the protective reaction for signature severity levels. These settings
instruct clients what to do when an attack or suspicious behavior is detected.
Each signature has one of four severity levels:
High
— Signatures of clearly identifiable security threats or malicious actions. These
signatures are specific to well-identified exploits and are mostly non-behavioral in nature.
Prevent these signatures on every system.
Medium
— Signatures of behavioral activity where applications operate outside their
envelope. Prevent these signatures on critical systems, as well as on web servers and SQL
servers.
Low
— Signatures of behavioral activity where applications and system resources are locked
and cannot be changed. Preventing these signatures increases the security of the underlying
system, but additional fine-tuning is needed.
Information
— Signatures of behavioral activity where applications and system resources
are modified and might indicate a benign security risk or an attempt to access sensitive
system information. Events at this level occur during normal system activity and generally
are not evidence of an attack.
These severity levels indicate potential danger to a system and enable you to define specific
reactions for different levels of potential harm. You can modify the severity levels and reactions
for all signatures. For example, when suspicious activity is unlikely to cause damage, you can
select
ignore
as the reaction. When an activity is likely to be dangerous, you can set
prevent
as the reaction.
Policy selections
This policy category contains six preconfigured policies and an editable
My Default
policy,
based on the McAfee Default policy. You can view and duplicate preconfigured policies; you
can, create, edit, rename, duplicate, delete, and export custom policies.
Preconfigured policies include:
Table 6: IPS Protection policies
Function
Name
Prevent high-severity signatures and ignore the rest.
Basic Protection (McAfee Default)
Prevent high- and medium-severity signatures and ignore
the rest.
Enhanced Protection
Configuring IPS Policies
Set the reaction for IPS signatures
35
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5