McAfee HISCDE-AB-IA Product Guide - Page 40

Configuring IPS signatures, Menu | Policy | Policy Catalog, Host Intrusion Prevention: IPS, Product

Page 40 highlights

Configuring IPS Policies Define IPS protection Network IPS signatures Network-based intrusion prevention signatures detect and prevent known network-based attacks that arrive on the host system. They appear in the same list of signatures as the host-based signatures. Each signature has a description and a default severity level. With appropriate privilege levels, an administrator can modify the severity level of a signature. You can create exceptions for network-based signatures; however, you cannot specify any additional parameter attributes such as operating system user or process name. Advanced details contain network-specific parameters, for example IP addresses, which you can specify. Events generated by network-based signatures are displayed along with the host-based events in the Events tab and exhibit the same behavior as host-based events. To work with signatures, click the Signatures tab in the IPS Rules policy. Configuring IPS signatures Edit default signatures, add custom signatures, and move signatures to another policy from the Signatures tab of the IPS Rules policy. Task For option definitions, click ? in the interface. 1 Click Menu | Policy | Policy Catalog and select Host Intrusion Prevention: IPS in the Product list and IPS Rules in the Category list. The list of policies appears. 2 Under Actions, click Edit to make changes on the IPS Rules page, then click the Signatures tab. 3 Do any of the following: To... Find a signature in the list Edit a signature Do this... Use the filters at the top of the signatures list. You can filter on signature severity, type, platform, log status, whether client rules are allowed, or specific text that includes signature name, notes, or content version. Click Clear to remove filter settings. Under Actions, click Edit. • If the signature is a default signature, you can modify the Severity Level, Client Rules, or Log Status settings, and enter notes in the Note box to document the change. Click OK to save any modifications. Edited default signatures can be reverted to their default settings by clicking Revert under Actions. NOTE: When you edit a signature and save the change, the signature is resorted in the list. As a result, you might need to search the list to find the edited signature. • If the signature is a custom signature, modify the Severity Level, Client Rules, Log Status or Description settings, and enter notes in the Note box to document the change. Click OK to save any modifications. NOTE: You can make changes to several signatures at once, by selecting the signatures and clicking Edit 40 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Network IPS signatures
Network-based intrusion prevention signatures detect and prevent known network-based attacks
that arrive on the host system. They appear in the same list of signatures as the host-based
signatures.
Each signature has a description and a default severity level. With appropriate privilege levels,
an administrator can modify the severity level of a signature.
You can create exceptions for network-based signatures; however, you cannot specify any
additional parameter attributes such as operating system user or process name. Advanced
details contain network-specific parameters, for example IP addresses, which you can specify.
Events generated by network-based signatures are displayed along with the host-based events
in the Events tab and exhibit the same behavior as host-based events.
To work with signatures, click the Signatures tab in the IPS Rules policy.
Configuring IPS signatures
Edit default signatures, add custom signatures, and move signatures to another policy from the
Signatures tab of the IPS Rules policy.
Task
For option definitions, click
?
in the interface.
1
Click
Menu | Policy | Policy Catalog
and select
Host Intrusion Prevention: IPS
in
the
Product
list and
IPS Rules
in the
Category
list. The list of policies appears.
2
Under
Actions
, click
Edit
to make changes on the
IPS Rules
page, then click the
Signatures
tab.
3
Do any of the following:
Do this...
To...
Use the filters at the top of the signatures list. You can
filter on signature severity, type, platform, log status,
Find a signature in the list
whether client rules are allowed, or specific text that
includes signature name, notes, or content version.
Click
Clear
to remove filter settings.
Under
Actions
, click
Edit
.
Edit a signature
If the signature is a default signature, you can
modify the
Severity Level
,
Client Rules
, or
Log
Status
settings, and enter notes in the
Note
box
to document the change. Click
OK
to save any
modifications. Edited default signatures can be
reverted to their default settings by clicking
Revert
under Actions.
NOTE:
When you edit a signature and save the
change, the signature is resorted in the list. As a
result, you might need to search the list to find the
edited signature.
If the signature is a custom signature, modify the
Severity Level
,
Client Rules
,
Log Status
or
Description
settings, and enter notes in the
Note
box to document the change. Click
OK
to save any
modifications.
NOTE:
You can make changes to several signatures at
once, by selecting the signatures and clicking
Edit
Configuring IPS Policies
Define IPS protection
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
40