McAfee HISCDE-AB-IA Product Guide - Page 42

Creating custom signatures with a wizard, FAQ — Use of wildcards in IPS Rules, Signatures

Page 42 highlights

Configuring IPS Policies Define IPS protection Standard method Expert method file description, file name, MD5 hash fingerprint, or signer. 5 Click OK and the rule is added to the list at the top of the Subrule tab. The rule is compiled and the syntax is verified. If the rule fails verification, a dialog box describing the error appears. Fix the error and verify the rule again. For details in working with class types, operations, and parameters, aee the appropriate class section of Writing Custom Signatures and Exceptions. 5 Click OK. NOTE: You can include multiple rules in a signature. Creating custom signatures with a wizard Use the custom signature wizard to simplify creating new signatures. NOTE: Signatures created with the wizard do not offer any flexibility for the operations that the signature is protecting because you cannot change, add, or delete operations. Task For option definitions, click ? in the interface. 1 On the IPS Rules Signatures tab, click New (Wizard). 2 On the Basic Information tab, type a name and select the platform, severity level, log status, and whether to allow the creation of client rules. Click Next to continue. 3 On the Description tab, type a description of what the signature is protecting. This description appears in the IPS Event when the signature is triggered. 4 On the Rule Definition tab, select the item to protect against modifications and enter details. 5 Click OK. FAQ - Use of wildcards in IPS Rules Host IPS Rules permits the use of wildcards when entering values in certain fields. Which wildcards can I use for path and address values? For paths of files, registry keys, executables, and URLs, use these wildcards: Character ? (question mark) * (one asterisk) ** (two asterisks) | (pipe) Definition A single character. Multiple characters, excluding / and \ . Use to match the root-level contents of a folder with no subfolders. Multiple characters, including / and \ . Wildcard escape. NOTE: For ** the escape is |*|*. 42 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Expert method
Standard method
file description, file name, MD5 hash fingerprint,
or signer.
5
Click
OK
and the rule is added to the list at the
top of the Subrule tab. The rule is compiled and
the syntax is verified. If the rule fails verification,
a dialog box describing the error appears. Fix
the error and verify the rule again.
For details in working with class types, operations, and parameters, aee the appropriate
class section of
Writing Custom Signatures and Exceptions
.
5
Click
OK
.
NOTE:
You can include multiple rules in a signature.
Creating custom signatures with a wizard
Use the custom signature wizard to simplify creating new signatures.
NOTE:
Signatures created with the wizard do not offer any flexibility for the operations that the
signature is protecting because you cannot change, add, or delete operations.
Task
For option definitions, click
?
in the interface.
1
On the IPS Rules
Signatures
tab, click
New (Wizard)
.
2
On the
Basic Information
tab, type a name and select the platform, severity level, log
status, and whether to allow the creation of client rules. Click
Next
to continue.
3
On the
Description
tab, type a description of what the signature is protecting. This
description appears in the
IPS Event
when the signature is triggered.
4
On the
Rule Definition
tab, select the item to protect against modifications and enter
details.
5
Click
OK
.
FAQ — Use of wildcards in IPS Rules
Host IPS Rules permits the use of wildcards when entering values in certain fields.
Which wildcards can I use for path and address values?
For paths of files, registry keys, executables, and URLs, use these wildcards:
Definition
Character
A single character.
? (question mark)
Multiple characters, excluding / and \ . Use to match the
root-level contents of a folder with no subfolders.
* (one asterisk)
Multiple characters, including / and \ .
** (two asterisks)
Wildcard escape.
NOTE:
For ** the escape is |*|*.
| (pipe)
Configuring IPS Policies
Define IPS protection
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
42